"value":"Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to\u00a0\n\n1.9.03.009\n\n have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.\n\n"
"value":"\n\n<span style=\"background-color: rgb(255, 255, 255);\">Delta Electronics fixed the reported vulnerability in version 1.9.03.009 and recommends all users update affected systems. Users can </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.deltaww.com/en-US/Customer-Service\">contact the front end sales or FAEs</a><span style=\"background-color: rgb(255, 255, 255);\"> to get this version.</span>\n\n<br>"
}
],
"value":"\nDelta Electronics fixed the reported vulnerability in version 1.9.03.009 and recommends all users update affected systems. Users can contact the front end sales or FAEs https://www.deltaww.com/en-US/Customer-Service \u00a0to get this version.\n\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Y4er working with Trend Micro Zero Day Initiative reported this vulnerability to CISA."