Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3214


Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.


Published

2022-09-16T19:15:10.087

Last Modified

2024-11-21T07:19:04.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-798
  • Type: Secondary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application deltaww diaenergie < 1.9.03.009 Yes

References