ICSA-22-307-03 Delta Industrial Automation DIALink Path traversal
Published Dec 1, 2022
8.1
HIGHCVSS 3.1
EPSS 2.43%
Description
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
Affected products
-
- Version 0StatusaffectedConstraints<1.5.0.0 Beta 4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Delta Industrial Automation | DIALink | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Delta Industrial Automation has created v1.5.0.0 Beta 4 to address this vulnerability. Delta Industrial Automation will not make this update an official release; users may obtain this updated version via Delta field application engineering (FAEs) or contacting Delta Industrial Automation directly.
References (1)
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.