CVE-2022-2969
ICSA-22-307-03 Delta Industrial Automation DIALink Path traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
Las versiones DIALink de Delta Industrial Automation anteriores a v1.5.0.0 Beta 4 utilizan una entrada externa para construir un nombre de ruta destinado a identificar un archivo o directorio ubicado debajo de un directorio principal restringido. Sin embargo, el software no neutraliza adecuadamente los elementos especiales dentro del nombre de la ruta, lo que puede hacer que el nombre de la ruta se resuelva en una ubicaciĆ³n fuera del directorio restringido.
This vulnerability allows remote attackers to create arbitrary files on affected installations of Delta Industrial Automation DIALink. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the opcua endpoint of the web service, which listens on TCP port 5000 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of the web service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-23 CVE Reserved
- 2022-12-01 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Deltaww Search vendor "Deltaww" | Dialink Search vendor "Deltaww" for product "Dialink" | < 1.5.0.0 Search vendor "Deltaww" for product "Dialink" and version " < 1.5.0.0" | - |
Affected
| ||||||
Deltaww Search vendor "Deltaww" | Dialink Search vendor "Deltaww" for product "Dialink" | 1.5.0.0 Search vendor "Deltaww" for product "Dialink" and version "1.5.0.0" | beta3 |
Affected
|