CVE-2021-38403: Delta Electronics DIALink
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Delta Electronics DIALink vulnerability?
The vulnerability ID for the Delta Electronics DIALink vulnerability is CVE-2021-38403.
What is the severity level of the Delta Electronics DIALink vulnerability?
The severity level of the Delta Electronics DIALink vulnerability is medium (4.8).
How does the Delta Electronics DIALink vulnerability affect the software?
The Delta Electronics DIALink vulnerability allows an authenticated attacker to inject arbitrary JavaScript code into the parameter supplier of the API maintenance, enabling remote code execution.
How can I fix the Delta Electronics DIALink vulnerability?
To fix the Delta Electronics DIALink vulnerability, update to a version newer than 1.2.4.0.
Where can I find more information about the Delta Electronics DIALink vulnerability?
More information about the Delta Electronics DIALink vulnerability can be found at the following link: https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02