CVE-2022-2969

HIGH

Delta Industrial Automation DIALink < 1.5.0.0 Beta 4 - Path Traversal

Title source: llm
STIX 2.1

Description

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03

Scores

CVSS v3 8.1
EPSS 0.0026
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
deltaww/dialink 1.5.0.0 beta3
deltaww/dialink < 1.5.0.0
Published Dec 01, 2022
Tracked Since Feb 18, 2026