CVE-2024-4548 is a critical SQL injection vulnerability affecting Delta Electronics DIAEnergie v1.10.1.8610 and earlier. An unauthenticated remote attacker can exploit this flaw by manipulating the fourth field of a 'RecalculateHDMWYC' message processed by CEBC.exe. With a CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability of the affected system. While not listed on CISA's KEV catalog, a Metasploit module exists, indicating readily available exploit code, though there is currently no public community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.01.004CPE matchmatch criteria | cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:* | ||
>= 0, <= 1.10.1.8610CPE match | cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.