HTTP: Delta Industrial Automation DIAEnergie SQL Injection

This signature detects attempts to exploit a known vulnerability against Delta. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

SQL Injection in FtyInfoSetting.aspxin Delta Electronics DIAEnergie versions prior tov1.9.02.001allows an attacker to inject SQL queries via Network

Affected Products

Deltaww diaenergie

References

CVE: CVE-2022-43452

Short Name
HTTP:SQL:INJ:DELTA-IND-DIAE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Automation CVE-2022-43452 DIAEnergie Delta Industrial Injection SQL
Release Date
02/02/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3647
False Positive
Unknown
Vendors

Deltaww

Found a potential security threat?