CVE-2021-38420: Delta Electronics DIALink
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38420?
CVE-2021-38420 is a vulnerability in Delta Electronics DIALink versions 1.2.4.0 and prior that gives extensive permissions to low-privileged user accounts, potentially allowing an attacker to modify the installation directory and upload malicious files.
What is the severity of CVE-2021-38420?
The severity of CVE-2021-38420 is rated as high with a CVSS score of 7.8.
How does CVE-2021-38420 affect Delta Electronics DIALink?
CVE-2021-38420 affects Delta Electronics DIALink versions 1.2.4.0 and prior by granting extensive permissions to low-privileged user accounts.
How can an attacker exploit CVE-2021-38420?
An attacker can exploit CVE-2021-38420 by modifying the installation directory and uploading malicious files.
Is there a fix for CVE-2021-38420?
At the moment, there is no specific fix available for CVE-2021-38420. It is recommended to follow the recommendations provided by the vendor and apply any security patches or updates when they become available.