{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-02T06:49:47.283","vulnerabilities":[{"cve":{"id":"CVE-2022-2969","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2022-12-01T18:15:10.207","lastModified":"2026-06-17T04:42:54.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory."},{"lang":"es","value":"Las versiones DIALink de Delta Industrial Automation anteriores a v1.5.0.0 Beta 4 utilizan una entrada externa para construir un nombre de ruta destinado a identificar un archivo o directorio ubicado debajo de un directorio principal restringido. Sin embargo, el software no neutraliza adecuadamente los elementos especiales dentro del nombre de la ruta, lo que puede hacer que el nombre de la ruta se resuelva en una ubicación fuera del directorio restringido."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Delta Industrial Automation","product":"DIALink","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.5.0.0 Beta 4","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-16T15:49:14.906906Z","id":"CVE-2022-2969","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:deltaww:dialink:*:*:*:*:*:*:*:*","versionEndExcluding":"1.5.0.0","matchCriteriaId":"0763E298-F79A-4604-B963-139473FC1368"},{"vulnerable":true,"criteria":"cpe:2.3:a:deltaww:dialink:1.5.0.0:beta3:*:*:*:*:*:*","matchCriteriaId":"8FC7C242-820D-4CF0-B408-78BC13C76BBE"}]}]}],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-03","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}