Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.
Workaround:
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02 | third party advisory us government resource |