Vulnerabilities > CVE-2021-38424 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Deltaww Dialink 1.2.4.0

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
deltaww
CWE-1236

Summary

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

Vulnerable Configurations

Part Description Count
Application
Deltaww
1