← Back to CVE List
Vulnerability Intelligence Report
ICSA-22-307-03 Delta Industrial Automation DIALink Path traversal

CVE-2022-2969

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

No Active Exploit Signals
CVSS Base Score
8.1
HIGH
Exploitability:2.9
Impact Score:5.2
EPSS Probability:2.28%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Path Traversa

Affected Products & Versions

Vendor Product Affected Versions
Delta Industrial Automation DIALink 0 < 1.5.0.0 Beta 4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.283%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA
Reserved2022-08-23T15:43:56
Published2022-12-01T17:08:19
Last Updated2025-04-16T16:05:33

LINK COPIED TO CLIPBOARD