HTTP: Delta Industrial Automation DIAEnergie Arbitrary File Upload

This signature detects attempts to exploit a known vulnerability against Delta Industrial Automation DIAEnergie. A successful attack can lead to arbitrary file upload and arbitrary code execution.

Extended Description

Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

Affected Products

Deltaww diaenergie

Short Name
HTTP:CTS:DELTA-IAD-FILE-UPLD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Arbitrary Automation CVE-2021-32955 CVE-2022-25347 DIAEnergie Delta File Industrial Upload
Release Date
10/25/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Deltaww

CVSS Score

7.5

Found a potential security threat?