Unrated severityNVD Advisory· Published Sep 16, 2022· Updated Aug 3, 2024
Delta Electronics DIAEnergy Use of Hard-coded Credentials
CVE-2022-3214
Description
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to
1.9.03.009
have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.
Affected products
1- Range: all
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-256-03mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.