CVE-2022-2969: ICSA-22-307-03 Delta Industrial Automation DIALink Path traversal
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-2969.
What is the affected software?
The affected software is Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4.
What is the severity of CVE-2022-2969?
The severity of CVE-2022-2969 is high with a CVSS score of 7.5.
How does CVE-2022-2969 exploit the software?
CVE-2022-2969 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname.
Is there a fix available for CVE-2022-2969?
Yes, the fix for CVE-2022-2969 is to update to Delta Industrial Automation DIALink version 1.5.0.0 Beta 4 or later.