← Vulnerability feed

Vulnerability record · CVE-2021-38390 · published 30 August 2021

CVE-2021-38390: Deltaww diaenergie sql injection vulnerability

Deltaww · Diaenergie

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

9.8 CVSS 3.1 Critical EPSS 20% · top 2.7% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 10.0
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://us-cert.cisa.gov/ics/advisories/icsa-21-238-03 Third Party AdvisoryUS Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-238-03 Third Party AdvisoryUS Government Resource

Track CVE-2021-38390 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4547Deltaww diaenergie improper input validation vulnerabilityA SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is sp…EPSS 1.9%9.8CVE-2024-4548Deltaww diaenergie improper input validation vulnerabilityAn SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is s…EPSS 29%9.8CVE-2024-25574Deltaww diaenergie sql injection vulnerabilitySQL injection vulnerability exists in GetDIAE_usListParameters.EPSS 8.8%9.8CVE-2022-43774Deltaww diaenergie sql injection vulnerabilityThe HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a…EPSS 0.75%9.8CVE-2022-43775Deltaww diaenergie sql injection vulnerabilityThe HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote…EPSS 21%9.8CVE-2022-3214Deltaww diaenergie hard-coded credentials vulnerabilityDelta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…EPSS 2.0%9.8CVE-2022-1367Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an at…EPSS 19%9.8CVE-2022-1369Deltaww diaenergie sql injection vulnerabilityDelta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-38390), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.