First published: Wed Nov 03 2021(Updated: )
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dialink | <=1.2.4.0 | |
Delta Electronics DIALink | <=1.2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38420 is a vulnerability in Delta Electronics DIALink versions 1.2.4.0 and prior that gives extensive permissions to low-privileged user accounts, potentially allowing an attacker to modify the installation directory and upload malicious files.
The severity of CVE-2021-38420 is rated as high with a CVSS score of 7.8.
CVE-2021-38420 affects Delta Electronics DIALink versions 1.2.4.0 and prior by granting extensive permissions to low-privileged user accounts.
An attacker can exploit CVE-2021-38420 by modifying the installation directory and uploading malicious files.
At the moment, there is no specific fix available for CVE-2021-38420. It is recommended to follow the recommendations provided by the vendor and apply any security patches or updates when they become available.