Lucene search

K
cvelistIcscertCVELIST:CVE-2021-38403
HistoryNov 03, 2021 - 7:05 p.m.

CVE-2021-38403 Delta Electronics DIALink

2021-11-0319:05:15
CWE-79
icscert
www.cve.org
5
delta electronics dialink
cross-site scripting
api maintenance
remote code execution

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

33.0%

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

CNA Affected

[
  {
    "product": "DIALink",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThanOrEqual": "1.2.4.0",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

33.0%

Related for CVELIST:CVE-2021-38403