First published: Tue Dec 13 2022(Updated: )
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dialink | <=1.4.0.0 | |
Delta Electronics Delta Industrial Automation DIALink: Version 1.4.0.0 and prior |
Mitigation measures have been added in DIALink v1.5.0.0. Delta Electronics recommends users contact Delta Electronics customer service https://www.deltaww.com/en/customerService or a Delta Electronics representative for this release, as it will not be released publicly.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security vulnerability is CVE-2022-2660.
CVE-2022-2660 has a severity level of critical, with a severity value of 7.5.
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are affected by CVE-2022-2660.
CVE-2022-2660 could allow an attacker to decrypt sensitive data and compromise the machine.
At the moment, there is no available fix for CVE-2022-2660. It is recommended to apply mitigations provided by the vendor or follow any security advisories.