Executive brief
Delta Electronics DIAView, an industrial SCADA software used for monitoring and controlling manufacturing processes, contains a critical security flaw. This vulnerability allows unauthorized individuals to access sensitive system functions without providing any login credentials. An attacker could exploit this to disrupt industrial operations, steal proprietary data, or gain full control over the management system.
Technical details
Delta Electronics DIAView versions prior to 4.4.0 are affected by a missing authentication vulnerability (CWE-306) in critical functional components. The flaw allows a remote, unauthenticated attacker to execute sensitive commands or access restricted data over the network without any user interaction. Given the CVSS score of 9.8, the vulnerability likely permits full compromise of confidentiality, integrity, and availability. Users are advised to update to DIAView version 4.4.0 or later to mitigate these risks.
Affected products
- Delta Electronics DIAView versions up to (excluding) 4.4.0
Timeline
- 2026-01-15: disclosed
- 2026-01-16: advisory: NVD published date