CVE-2022-3214 - CVE House
Back to Database
Status published Critical CVE-2022-3214

Delta Electronics DIAEnergy Use of Hard-coded Credentials

Vulnerability Description

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3214

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Y4er working with Trend Micro Zero Day Initiative reported this vulnerability to CISA.

Affected Vendor

Delta Electronics

View all reports →

Affected Software

DIAEnergy
Vulnerable Versions:
all

Timeline

Official Publish: September 16th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)