Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-84837
HistoryOct 22, 2021 - 12:00 a.m.

DIALink Cross-Site Scripting Vulnerability

2021-10-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
3
dialink
delta electronics
device networking
cnc machines
plc-controlled machines
api
modbuswriter-reader
remote code execution

EPSS

0.001

Percentile

33.0%

DIALink is a device networking platform from Delta Electronics that allows effective management of CNC machines and PLC-controlled machines, collects field device data and interfaces with the upper management platform through a unified interface, and provides visual information to reflect process parameters and device operating status. scripting vulnerability. An attacker can use this vulnerability to inject arbitrary JavaScript code into the deviceName parameter of the API modbusWriter-Reader and execute the code remotely.

EPSS

0.001

Percentile

33.0%

Related for CNVD-2021-84837