Vulnerability CVE-2022-40967


Published: 2022-10-27

Description:
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

 References:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06

Copyright 2025, cxsecurity.com

 

Back to Top