Back

HIGH

ICSA-22-307-03 Delta Industrial Automation DIALink Path traversal

Published Dec 1, 2022

Description

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

Affected products

Remediation

Vendor solution

Delta Industrial Automation has created v1.5.0.0 Beta 4 to address this vulnerability. Delta Industrial Automation will not make this update an official release; users may obtain this updated version via Delta field application engineering (FAEs) or contacting Delta Industrial Automation directly.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Dec 1, 2022
Updated Apr 16, 2025
Reserved Aug 23, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a