

Rewterz Threat Alert – Snake Keylogger Malware – Active IOCs
March 18, 2024
Rewterz Threat Advisory – Multiple Apache Products Vulnerabilities
March 18, 2024
Rewterz Threat Alert – Snake Keylogger Malware – Active IOCs
March 18, 2024
Rewterz Threat Advisory – Multiple Apache Products Vulnerabilities
March 18, 2024Severity
High
Analysis Summary
CVE-2024-28045 CVSS:4.6
Delta Electronics DIAEnergie is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2024-25567 CVSS:8.1
Delta Electronics DIAEnergie could allow a remote attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to write arbitrary files on the system.
CVE-2024-28171 CVSS:8.1
Delta Electronics DIAEnergie could allow a remote attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to write arbitrary files on the system.
CVE-2024-25574 CVSS:8.8
Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_usListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2024-23494 CVSS:8.8
Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_unListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2024-23975 CVSS>8.8
Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_slogListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2024-28040 CVSS:8.8
Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the GetDIAE_astListParameters, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2024-25937 CVSS:8.8
Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the DIAE_tagHandler.ashx script, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2024-28891 CVSS:8.8
Delta Electronics DIAEnergie is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements to the Handler_CFG.ashx script, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2024-28029 CVSS:8.8
Delta Electronics DIAEnergie could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper authorization validation. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain access to privileged functionality.
Impact
- Cross-Site Scripting
- Gain Access
- Data Manipulation
- Privilege Escalation
Indicators Of Compromise
CVE
- CVE-2024-28045
- CVE-2024-25567
- CVE-2024-28171
- CVE-2024-25574
- CVE-2024-23494
- CVE-2024-23975
- CVE-2024-28040
- CVE-2024-25937
- CVE-2024-28891
- CVE-2024-28029
Affected Vendors
Delta Electronics
Affected Products
- Delta Electronics DIAEnergie 1.10
Remediation
Upgrade to the latest version of DIAEnergie, available from the Delta Electronics Website.