CVE-2024-34032
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
03/05/2024
Last modified:
30/01/2025
Description
<br />
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.<br />
<br />
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:deltaww:diaenergie:1.10.00.005:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



