CVE-2022-2660: Critical severity delta electronics dialink vulnerability
Published Dec 13, 2022
·Updated
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
Affected Software
2 affected components
Delta Electronics Delta Industrial Automation DIALink: Version 1.4.0.0 and prior
Deltaww Dialink<=1.4.0.0
Remediation
Information
Mitigation measures have been added in DIALink v1.5.0.0.
Delta Electronics recommends users contact Delta Electronics customer service https://www.deltaww.com/en/customerService or a Delta Electronics representative for this release, as it will not be released publicly.
Event History
Dec 13, 2022
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
RemedyDescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via ICS·12:53 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security vulnerability?
The vulnerability ID of this security vulnerability is CVE-2022-2660.
2
What is the severity of CVE-2022-2660?
CVE-2022-2660 has a severity level of critical, with a severity value of 7.5.
3
Which software versions are affected by CVE-2022-2660?
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are affected by CVE-2022-2660.
4
What is the impact of CVE-2022-2660?
CVE-2022-2660 could allow an attacker to decrypt sensitive data and compromise the machine.
5
Is there a fix available for CVE-2022-2660?
At the moment, there is no available fix for CVE-2022-2660. It is recommended to apply mitigations provided by the vendor or follow any security advisories.