RULE(RULE ID:337193)

Rule General Information
Release Date: 2022-11-29
Rule Name: Delta Electronics DIAEnergie Stored Cross-Site Scripting Vulnerability (CVE-2022-41555)
Severity:
CVE ID:
Rule Protection Details
Description: The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Others
Reference: https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-06
Solutions
Refer to the announcement or patch by the vendor: https://www.deltaww.com/en-us/products/DIAEnergie-Industrial-Energy-Management-System/ALL/