First published: Thu Oct 21 2021(Updated: )
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dialink | <=1.2.4.0 | |
Delta Electronics DIALink | <=1.2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38411.
The affected software is Delta Electronics DIALink versions 1.2.4.0 and prior.
The severity level of CVE-2021-38411 is medium (4.8).
The vulnerability occurs due to an authenticated attacker injecting arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader.
The vulnerability may allow an attacker to remotely execute code.