PatchSiren cyber security CVE debrief
CVE-2024-42417 Delta Electronics CVE debrief
Delta Electronics DIAEnergie versions up to and including v1.10.01.008 contain an authenticated SQL injection vulnerability in the Handler_CFG.ashx script. An attacker with valid credentials can exploit this flaw to inject malicious SQL commands, potentially causing operational delays in the targeted industrial control system. The vulnerability carries a HIGH severity CVSS 3.1 score of 8.8, reflecting significant confidentiality, integrity, and availability impacts. CISA published advisory ICSA-24-277-03 on October 3, 2024, coordinating disclosure with the vendor. Delta Electronics has released version v1.10.01.009 to address this issue. Organizations should prioritize patching given the network-accessible attack vector and low attack complexity.
- Vendor
- Delta Electronics
- Product
- DIAEnergie
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-10-03
- Original CVE updated
- 2024-10-03
- Advisory published
- 2024-10-03
- Advisory updated
- 2024-10-03
Who should care
Organizations operating Delta Electronics DIAEnergie energy management systems in industrial environments, particularly critical infrastructure operators in energy, manufacturing, and building automation sectors. Security teams responsible for OT/ICS asset protection and vulnerability management programs should prioritize assessment and patching.
Technical summary
The vulnerability exists in the Handler_CFG.ashx script of Delta Electronics DIAEnergie, an industrial energy management system. The flaw permits authenticated attackers to inject arbitrary SQL commands through insufficient input validation. Successful exploitation can manipulate database queries, potentially causing denial of service conditions or operational delays in energy management operations. The attack requires network access and valid credentials but no user interaction, with low attack complexity. CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
HIGH
Recommended defensive actions
- Apply vendor patch: Update DIAEnergie to version v1.10.01.009 by contacting Delta Electronics regional sales or agents
- Review and restrict network access to DIAEnergie management interfaces to authorized administrative hosts only
- Implement network segmentation for industrial control systems per CISA ICS recommended practices
- Monitor Handler_CFG.ashx access logs for anomalous SQL-like patterns or unexpected query parameters
- Validate input sanitization on all authenticated endpoints in DIAEnergie deployments
- Apply principle of least privilege to DIAEnergie administrative accounts
Evidence notes
Vulnerability confirmed in DIAEnergie <=v1.10.01.008 per CISA CSAF product tree. SQL injection vector identified in Handler_CFG.ashx script. Authentication required (PR:L). Vendor fix available in v1.10.01.009.
Official resources
-
CVE-2024-42417 CVE record
CVE.org
-
CVE-2024-42417 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Coordinated disclosure via CISA ICS advisory ICSA-24-277-03