Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.





Advisories
Source ID Title
EUVD EUVD EUVD-2022-34906 Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.
Fixes

Solution

Mitigation measures have been added in DIALink v1.5.0.0.  Delta Electronics recommends users contact Delta Electronics customer service https://www.deltaww.com/en/customerService  or a Delta Electronics representative for this release, as it will not be released publicly.


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:04:37.830Z

Reserved: 2022-08-04T14:26:47.606Z

Link: CVE-2022-2660

cve-icon Vulnrichment

Updated: 2024-08-03T00:46:03.794Z

cve-icon NVD

Status : Modified

Published: 2022-12-13T22:15:09.910

Modified: 2024-11-21T07:01:27.747

Link: CVE-2022-2660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.