CVE-2021-38411: Delta Electronics DIALink
Published Nov 3, 2021
·Updated
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.
Affected Software
2 affected components
Delta Electronics DIALink<=1.2.4.0
Deltaww Dialink<=1.2.4.0
Event History
Nov 3, 2021
CVE Published
via MITRE·07:04 PM
Data Sourced
via MITRE·07:04 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38411.
2
What is the affected software?
The affected software is Delta Electronics DIALink versions 1.2.4.0 and prior.
3
What is the severity level of CVE-2021-38411?
The severity level of CVE-2021-38411 is medium (4.8).
4
How does the vulnerability occur?
The vulnerability occurs due to an authenticated attacker injecting arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader.
5
What is the potential impact of this vulnerability?
The vulnerability may allow an attacker to remotely execute code.