Beveiligingsadvies

CVE-2022-3214

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-09-16 18:05:41
Laatst bijgewerkt 2024-08-03 01:00:10
Toegewezen door icscert
CVSS-score 9.8
Status PUBLISHED

Beschrijving

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.