Lucene search

K
cveIcscertCVE-2022-3214
HistorySep 16, 2022 - 7:15 p.m.

CVE-2022-3214

2022-09-1619:15:10
CWE-798
icscert
web.nvd.nist.gov
48
4
cve-2022-3214
nvd
delta industrial automation
diaenergy
industrial energy management system
cwe-798
hard-coded credentials
remote code execution

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

74.5%

Delta Industrial Automation’s DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to

1.9.03.009

have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.

Affected configurations

Nvd
Node
deltawwdiaenergieRange<1.9.03.009
VendorProductVersionCPE
deltawwdiaenergie*cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "DIAEnergy",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThan": "1.9.03.009",
        "status": "affected",
        "version": "all",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

74.5%

Related for CVE-2022-3214