CVE-2022-4616: Command Injection
Published Jan 12, 2023
·Updated
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.
Affected Software
3 affected components
: Delta Industrial Automation DX-3021L9 versions prior to V1.24
Deltaww Dx-3021l9 Firmware<1.24
Deltaww Dx-3021l9
Remediation
Information
Delta fixed this vulnerability and released a new patch, which is available on the Delta download center https://downloadcenter.deltaww.com/en-US/DownloadCenter .
Event History
Jan 12, 2023
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
RemedyDescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via ICS·01:55 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-4616?
The severity of CVE-2022-4616 is critical with a CVSS score of 9.1.
2
How can an attacker exploit CVE-2022-4616?
An attacker can exploit CVE-2022-4616 by performing command injection through the network diagnosis page.
3
What can a remote unauthenticated user do if they exploit CVE-2022-4616?
If a remote unauthenticated user exploits CVE-2022-4616, they can add files, delete files, and change file permissions.
4
What is the affected software version of CVE-2022-4616?
The affected software version of CVE-2022-4616 is Delta DX-3021 versions prior to 1.24.
5
How can I fix CVE-2022-4616?
To fix CVE-2022-4616, update to Delta DX-3021 version 1.24 or later.