Vulnerability Intelligence Report
Delta Electronics DIALink
CVE-2021-38416
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-427 ↗CWE-427 Uncontrolled Search Path Element
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Delta Electronics | DIALink | All <= 1.2.4.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.246%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA |
| Reserved | 2021-08-10T00:00:00 |
| Published | 2021-11-03T19:05:48 |
| Patch Date | 2021-10-21 |
| Last Updated | 2024-09-16T18:54:21 |
Community Chatter & Buzz