CVE-2021-38424: Delta Electronics DIALink
Published Nov 3, 2021
·Updated
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.
Affected Software
2 affected components
Delta Electronics DIALink<=1.2.4.0
Deltaww Dialink<=1.2.4.0
Event History
Nov 3, 2021
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38424.
2
What is the affected software?
The affected software is Delta Electronics DIALink versions 1.2.4.0 and prior.
3
What is the severity level of CVE-2021-38424?
The severity level of CVE-2021-38424 is high with a CVSS score of 7.8.
4
What is the CWE ID of CVE-2021-38424?
The CWE ID of CVE-2021-38424 is 1236.
5
How can I fix CVE-2021-38424?
To fix CVE-2021-38424, it is recommended to update Delta Electronics DIALink to a version higher than 1.2.4.0.