Delta Electronics DIALink
CVE-2021-38424

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 November 2021

Summary

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

Affected Version(s)

DIALink All <= 1.2.4.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.