First published: Fri Sep 16 2022(Updated: )
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to 1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Diaenergie | <1.9.0 | |
Deltaww Diaenergie | <1.9.03.009 | |
Delta Electronics DIAEnergie: versions prior to 1.9.03.009 |
Delta Electronics fixed the reported vulnerability in version 1.9.03.009 and recommends all users update affected systems. Users can contact the front end sales or FAEs https://www.deltaww.com/en-US/Customer-Service to get this version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-3214.
The severity of CVE-2022-3214 is critical with a CVSS score of 9.8.
The affected software is Delta Industrial Automation's DIAEnergy version up to 1.9.0.
CWE-798 refers to the Use of Hard-coded Credentials vulnerability.
To fix CVE-2022-3214, update Delta Industrial Automation's DIAEnergy to version 1.9.03.009 or later.