Successful exploitation of these remotely exploitable vulnerabilities, discovered by Michael Heinzl, could allow an attacker to inject arbitrary code to retrieve and modify database contents and execute system commands.
Delta Electronics reports the following versions of DIAEnergie, an industrial energy management system: All versions prior to v1.9.01.002.
In one issue, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.
In addition, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.
CVE-2022-40965 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.7.
Also, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
CVE-2022-41555 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.7.
In another issue, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.
CVE-2022-41702 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.7.
In addition, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.
CVE-2022-41651 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.7.
Also, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
CVE-2022-40965 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.8.
In another issue, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
CVE-2022-41133 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.8.
In addition, the affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.
CVE-2022-41773 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.8.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target these vulnerabilities. However, an attacker with low skill level could leverage these low complexity vulnerabilities.
Taiwan-based Delta did not publicly release v1.9.01.002. Users are encouraged to contact Delta front-end sales or agents to get this updated version.

