Lucene search

K
nvd[email protected]NVD:CVE-2022-2969
HistoryDec 01, 2022 - 6:15 p.m.

CVE-2022-2969

2022-12-0118:15:10
CWE-22
web.nvd.nist.gov
1
delta industrial automation
dialink
security vulnerability
external input
pathname
restriction bypass

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

46.5%

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

Affected configurations

NVD
Node
deltawwdialinkRange<1.5.0.0
OR
deltawwdialinkMatch1.5.0.0beta3

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

46.5%

Related for NVD:CVE-2022-2969