Lucene search

K
cvelistIcscertCVELIST:CVE-2021-38416
HistoryNov 03, 2021 - 7:05 p.m.

CVE-2021-38416 Delta Electronics DIALink

2021-11-0319:05:48
CWE-427
icscert
www.cve.org
2
delta electronics
dialink
insecure library loading
dll hijacking
system takeover

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

10.4%

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

CNA Affected

[
  {
    "product": "DIALink",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThanOrEqual": "1.2.4.0",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

10.4%

Related for CVELIST:CVE-2021-38416