CVE-2022-3214

Critical
|9.8
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to remotely execute malicious code on Delta's DIAEnergy system by uploading harmful files, thanks to hard-coded login credentials that can be exploited. This issue affects versions before 1.9.03.009, meaning any system running an older version is at risk.

Technical Description

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$13,000($5K-$15K)
Vendor Response
Grade FPatched in 1257 days

Quick Information

Published

Sep 16, 2022

over 3 years ago

Last Modified

Feb 25, 2026

about 1 month ago

Vendor

deltaww

Product

diaenergie