ZDI-23-671: Delta Industrial Automation DIALink Directory Traversal Arbitrary File Creation Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Delta Industrial Automation DIALink. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-671?
ZDI-23-671 is considered a high-severity vulnerability due to its potential for unauthorized arbitrary file creation.
How do I fix ZDI-23-671?
To fix ZDI-23-671, install the latest security patches provided by Delta Industrial Automation for DIALink.
Can ZDI-23-671 be exploited without authentication?
No, ZDI-23-671 requires authentication, but the authentication mechanism can be bypassed.
What types of attacks are possible with ZDI-23-671?
With ZDI-23-671, remote attackers can create arbitrary files, which could lead to further exploitation of the system.
Is there a workaround for ZDI-23-671 if I cannot immediately patch?
Limit access to the affected DIALink installation to trusted users only as a temporary workaround for ZDI-23-671.