First published: Thu Jan 12 2023(Updated: )
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dx-3021l9 Firmware | <1.24 | |
Deltaww Dx-3021l9 | ||
: Delta Industrial Automation DX-3021L9 versions prior to V1.24 |
Delta fixed this vulnerability and released a new patch, which is available on the Delta download center https://downloadcenter.deltaww.com/en-US/DownloadCenter .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-4616 is critical with a CVSS score of 9.1.
An attacker can exploit CVE-2022-4616 by performing command injection through the network diagnosis page.
If a remote unauthenticated user exploits CVE-2022-4616, they can add files, delete files, and change file permissions.
The affected software version of CVE-2022-4616 is Delta DX-3021 versions prior to 1.24.
To fix CVE-2022-4616, update to Delta DX-3021 version 1.24 or later.