Executive brief
Delta Electronics DIAView, an industrial SCADA software used for monitoring and controlling manufacturing processes, contains a critical security flaw. The software uses fixed, unchangeable security keys for its encryption, which could allow an unauthorized person to bypass security measures. If exploited, an attacker could gain full control over the system, potentially leading to data theft, operational downtime, or unauthorized changes to industrial equipment.
Technical details
Delta Electronics DIAView is vulnerable to the use of hard-coded cryptographic keys (CWE-321). Because the same secret key is embedded across installations, an attacker who discovers the key can decrypt sensitive traffic, bypass authentication, or forge administrative commands. The vulnerability is exploitable over the network without any prior authentication or user interaction. Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability. Users are advised to update to version 4.4.0 or later to mitigate this risk.
Affected products
- Delta Electronics DIAView versions up to (excluding) 4.4.0
Timeline
- 2026-01-15: disclosed
- 2026-01-16: advisory