The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24876 | The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application. |
Fixes
Solution
No solution given by the vendor.
Workaround
Delta Electronics is aware of the vulnerabilities and is currently working on an update.
References
| Link | Providers |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-21-294-02 |
|
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-16T20:41:42.309Z
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38424
No data.
Status : Modified
Published: 2021-11-03T20:15:08.827
Modified: 2024-11-21T06:17:03.910
Link: CVE-2021-38424
No data.
OpenCVE Enrichment
No data.
EUVD