Lucene search

K
cve[email protected]CVE-2022-2969
HistoryDec 01, 2022 - 6:15 p.m.

CVE-2022-2969

2022-12-0118:15:10
CWE-22
web.nvd.nist.gov
26
cve
2022
2969
delta industrial automation
dialink
pathname
security vulnerability
nvd

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

Affected configurations

NVD
Node
deltawwdialinkRange<1.5.0.0
OR
deltawwdialinkMatch1.5.0.0beta3

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "DIALink",
    "vendor": "Delta Industrial Automation",
    "versions": [
      {
        "lessThan": "1.5.0.0 Beta 4",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

Related for CVE-2022-2969