CVE-2022-3214: Delta Electronics DIAEnergy Use of Hard-coded Credentials
Published Sep 16, 2022
·Updated
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to
1.9.03.009
have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.
Affected Software
3 affected components
Delta Electronics DIAEnergie: versions prior to 1.9.03.009
Deltaww Diaenergie<1.9.03.009
Deltaww Diaenergie<1.9.0
Remediation
Information
Delta Electronics fixed the reported vulnerability in version 1.9.03.009 and recommends all users update affected systems. Users can contact the front end sales or FAEs https://www.deltaww.com/en-US/Customer-Service to get this version.
Event History
Sep 16, 2022
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3214.
2
What is the severity of CVE-2022-3214?
The severity of CVE-2022-3214 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Delta Industrial Automation's DIAEnergy version up to 1.9.0.
4
What is CWE-798?
CWE-798 refers to the Use of Hard-coded Credentials vulnerability.
5
How can I fix CVE-2022-3214?
To fix CVE-2022-3214, update Delta Industrial Automation's DIAEnergy to version 1.9.03.009 or later.