CVE-2022-4616
 
Severity Score
9.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to
command injection through the network diagnosis page. This vulnerability
could allow a remote unauthenticated user to add files, delete files,
and change file permissions.
El servidor web en las versiones Delta DX-3021 anteriores a la 1.24 es vulnerable a la inyección de comandos a través de la página de diagnóstico de red. Esta vulnerabilidad podría permitir que un usuario remoto no autenticado agregue archivos, elimine archivos y cambie los permisos de los archivos.
*Credits:
Parul Sindhwad, Anurag M. Chevendra, Dr. Faruk Kazi from CoE-CNDS Lab, VJTI, Mumbai, India reported this vulnerability to CISA.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-12-19 CVE Reserved
- 2023-01-12 CVE Published
- 2023-05-24 First Exploit
- 2024-08-03 CVE Updated
- 2024-08-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-354-05 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/ahanel13/CVE-2022-4616-POC | 2023-05-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Deltaww Search vendor "Deltaww" | Dx-3021l9 Firmware Search vendor "Deltaww" for product "Dx-3021l9 Firmware" | < 1.24 Search vendor "Deltaww" for product "Dx-3021l9 Firmware" and version " < 1.24" | - |
Affected
| in | Deltaww Search vendor "Deltaww" | Dx-3021l9 Search vendor "Deltaww" for product "Dx-3021l9" | - | - |
Safe
|