First published: Wed May 17 2023(Updated: )
This vulnerability allows remote attackers to create arbitrary files on affected installations of Delta Industrial Automation DIALink. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Electronics DIALink |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-23-671 is considered a high-severity vulnerability due to its potential for unauthorized arbitrary file creation.
To fix ZDI-23-671, install the latest security patches provided by Delta Industrial Automation for DIALink.
No, ZDI-23-671 requires authentication, but the authentication mechanism can be bypassed.
With ZDI-23-671, remote attackers can create arbitrary files, which could lead to further exploitation of the system.
Limit access to the affected DIALink installation to trusted users only as a temporary workaround for ZDI-23-671.