Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-35190 Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.
Fixes

Solution

Delta Industrial Automation has created v1.5.0.0 Beta 4 to address this vulnerability. Delta Industrial Automation will not make this update an official release; users may obtain this updated version via Delta field application engineering (FAEs) or contacting Delta Industrial Automation directly.


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:05:33.867Z

Reserved: 2022-08-23T15:43:56.589Z

Link: CVE-2022-2969

cve-icon Vulnrichment

Updated: 2024-08-03T00:53:00.680Z

cve-icon NVD

Status : Modified

Published: 2022-12-01T18:15:10.207

Modified: 2024-11-21T07:02:00.377

Link: CVE-2022-2969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.