
CVE-2024-4549 – Delta Electronics DIAEnergie SQL Injection
https://notcve.org/view.php?id=CVE-2024-4549
06 May 2024 — A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system. Existe una vulnerabilidad de denegación de servicio en Delta Electronics DIAEnergie v1.10.1.8610 y anteriores. Al procesar un mensaje 'ICS Restart! • https://www.tenable.com/security/research/tra-2024-13 • CWE-400: Uncontrolled Resource Consumption •

CVE-2024-4548 – Delta Electronics DIAEnergie SQL Injection
https://notcve.org/view.php?id=CVE-2024-4548
06 May 2024 — An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field. Existe una vulnerabilidad SQLi en Delta Electronics DIAEnergie v1.10.1.8610 y anteriores cuando CEBC.exe procesa un mensaje 'RecalculateHDMWYC', que se divide en 4 campos utilizando el carácter '~' como separador. Un atacante re... • https://packetstorm.news/files/id/180334 • CWE-20: Improper Input Validation •

CVE-2024-4547 – Delta Electronics DIAEnergie Unauthenticated SQL Injection
https://notcve.org/view.php?id=CVE-2024-4547
06 May 2024 — A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field Existe una vulnerabilidad SQLi en Delta Electronics DIAEnergie v1.10.1.8610 y anteriores cuando CEBC.exe procesa un mensaje 'RecalculateScript', que se divide en 4 campos utilizando el carácter '~' como separador. Un atacante r... • https://www.tenable.com/security/research/tra-2024-13 • CWE-20: Improper Input Validation •

CVE-2024-34033 – Path Traversal vulnerability in Delta Electronics DIAEnergie
https://notcve.org/view.php?id=CVE-2024-34033
03 May 2024 — Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten. Delta Electronics DIAEnergie tiene una validación de entrada insuficiente, lo que permite realizar un ataque de path traversal y escribir fuera del directorio previsto. Si se especifica un nombre de archivo que ya existe en el sistem... • https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-02 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2024-34031 – SQL Injection vulnerability in Delta Electronics DIAEnergie
https://notcve.org/view.php?id=CVE-2024-34031
03 May 2024 — Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. Delta Electronics DIAEnergie es afectada por una vulnerabilidad de inyección SQL que existe en el script Handler_CFG.ashx. Un atacante autenticado puede aprovechar este problema para comprometer potencialmente el sistema en el que está implementado DIAEnergie. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-02 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-34032 – SQL Injection in Delta Electronics DIAEnergie
https://notcve.org/view.php?id=CVE-2024-34032
03 May 2024 — Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. Delta Electronics DIAEnergie es afectada por una vulnerabilidad de inyección SQL que existe en el endpoint GetDIACloudList. Un atacante autenticado puede aprovechar este problema para comprometer potencialmente el sistema en el que está implementado DIAEnergie. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-02 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-4192 – Stack-based Buffer Overflow vulnerability in Delta Electronics CNCSoft-G2 DOPSoft
https://notcve.org/view.php?id=CVE-2024-4192
30 Apr 2024 — Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Delta Electronics CNCSoft-G2 carece de una validación adecuada de la longitud de los datos proporcionados por el usuario antes de copiarlos en un búfer basado en pila de longitud fija. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el conte... • https://www.cisa.gov/news-events/ics-advisories/icsa-24-121-01 • CWE-121: Stack-based Buffer Overflow •

CVE-2024-28171 – Delta Electronics DIAEnergie Path traversal
https://notcve.org/view.php?id=CVE-2024-28171
21 Mar 2024 — It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten. Es posible realizar un ataque de path traversal y escribir fuera del directorio deseado. Si se especifica un nombre de archivo que ya existe en el sistema de archivos, se sobrescribirá el archivo original. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-12 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2024-25937 – Delta Electronics DIAEnergie SQL injection
https://notcve.org/view.php?id=CVE-2024-25937
21 Mar 2024 — SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. Existe una vulnerabilidad de inyección SQL en el script DIAE_tagHandler.ashx. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-12 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-1941 – Delta Electronics CNCSoft-B Stack-based Buffer Overflow
https://notcve.org/view.php?id=CVE-2024-1941
01 Mar 2024 — Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. Delta Electronics CNCSoft-B versiones 1.0.0.4 y anteriores son vulnerables a un desbordamiento de búfer en la región stack de la memoria, lo que puede permitir a un atacante ejecutar código arbitrario. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-B. User interaction is requ... • https://www.cisa.gov/news-events/ics-advisories/icsa-24-060-01 • CWE-121: Stack-based Buffer Overflow •