Rewterz
Rewterz Threat Alert – Snake Keylogger Malware – Active IOCs
March 18, 2024
Rewterz
Rewterz Threat Advisory – Multiple Apache Products Vulnerabilities
March 18, 2024

Rewterz Threat Advisory – ICS: Multiple Delta Electronics DIAEnergie Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-28045 CVSS:4.6

Delta Electronics DIAEnergie is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2024-25567 CVSS:8.1

Delta Electronics DIAEnergie could allow a remote attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to write arbitrary files on the system.

CVE-2024-28171 CVSS:8.1

Delta Electronics DIAEnergie could allow a remote attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to write arbitrary files on the system.

CVE-2024-25574 CVSS:8.8

Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_usListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2024-23494 CVSS:8.8

Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_unListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2024-23975 CVSS>8.8

Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_slogListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2024-28040 CVSS:8.8

Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_astListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2024-25937 CVSS:8.8

Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the DIAE_tagHandler.ashx script, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2024-28891 CVSS:8.8

Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the Handler_CFG.ashx script, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2024-28029 CVSS:8.8

Delta Electronics DIAEnergie could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper authorization validation. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain access to privileged functionality.

Impact

  • Cross-Site Scripting
  • Gain Access
  • Data Manipulation
  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2024-28045
  • CVE-2024-25567
  • CVE-2024-28171
  • CVE-2024-25574
  • CVE-2024-23494
  • CVE-2024-23975
  • CVE-2024-28040
  • CVE-2024-25937
  • CVE-2024-28891
  • CVE-2024-28029

Affected Vendors

Delta Electronics

Affected Products

  • Delta Electronics DIAEnergie 1.10

Remediation

Upgrade to the latest version of DIAEnergie, available from the Delta Electronics Website.

Delta Electronics Website