VDB

SEVD-2022-039-04

SEVD-2022-039-04 PUBLISHED CVSS 9.100000381469727 CRITICAL

Schneider Electric is aware of multiple vulnerabilities in its spaceLYnk, Wiser For KNX, and fellerLYnk products. spaceLYnk is a centralized solution that reduces energy and maintenance costs, increases comfort and flexibility, and simplifies building management. Wiser for KNX ,formerly known as homeLYnk, products are personalized energy efficiency solutions, offering a complete system based on open protocols: KNX, Modbus, BACnet and IP. fellerLYnk offers more flexibility in visualization and trend recording as well as functions such as presence simulation or time switches that the end customer can easily manage. Failure to apply the remediations provided below may risk a Cross-Site Request Forgery (CSRF), Missing Authentication, rate limit, or Stored Cross-Site Scripting (XSS) attack which could result in exfiltrated data and unauthorized access. March 2022 Update: The CVSS score has been updated for CVE-2022-22811 and CVE-2022-22812

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Schneider Electric Wiser for KNX (formerly homeLYnk) 2.7.0
Schneider Electric Wiser for KNX (formerly homeLYnk) V2.6.2 and prior
Schneider Electric fellerLYnk 2.7.0
Schneider Electric spaceLYnk 2.7.0
Schneider Electric fellerLYnk V2.6.2 and prior
Schneider Electric spaceLYnk V2.6.2 and prior

Timeline

  • Feb 8, 2022 CVE Published
  • Mar 8, 2022 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›