CVE-2022-22811 PUBLISHED CVSS 8.800000190734863 HIGH

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)

EPSS 0.10% · 28.4th percentile

Risk Scores

CVSS v2.0
8.800000190734863
EPSS Score
0.10%
28.4th percentile

Affected Products

VendorProductVersions
schneider-electricspacelynk_firmware0
schneider-electricfellerlynk_firmware0
schneider-electricwiser_for_knx_firmware0
n/aspaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)

Timeline

References

Open in Interactive Console →