// For flags

CVE-2022-4616

 

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to
command injection through the network diagnosis page. This vulnerability
could allow a remote unauthenticated user to add files, delete files,
and change file permissions.

El servidor web en las versiones Delta DX-3021 anteriores a la 1.24 es vulnerable a la inyección de comandos a través de la página de diagnóstico de red. Esta vulnerabilidad podría permitir que un usuario remoto no autenticado agregue archivos, elimine archivos y cambie los permisos de los archivos.

*Credits: Parul Sindhwad, Anurag M. Chevendra, Dr. Faruk Kazi from CoE-CNDS Lab, VJTI, Mumbai, India reported this vulnerability to CISA.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-12-19 CVE Reserved
  • 2023-01-12 CVE Published
  • 2023-05-24 First Exploit
  • 2024-08-03 CVE Updated
  • 2024-08-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Deltaww
Search vendor "Deltaww"
Dx-3021l9 Firmware
Search vendor "Deltaww" for product "Dx-3021l9 Firmware"
< 1.24
Search vendor "Deltaww" for product "Dx-3021l9 Firmware" and version " < 1.24"
-
Affected
in Deltaww
Search vendor "Deltaww"
Dx-3021l9
Search vendor "Deltaww" for product "Dx-3021l9"
--
Safe