Weak FTP Access in Schneider Electric Wiser and Related Products
CVE-2018-7779

7.5HIGH

Key Information:

Vendor
CVE Published:
19 April 2018

Summary

Schneider Electric products, including Wiser for KNX, homeLYnk, and spaceLYnk, are impacted by a vulnerability that allows unauthorized access due to weak and unprotected FTP configurations. This flaw can enable attackers to exploit the FTP access, potentially leading to compromised system integrity and confidentiality. Users are advised to review security measures and apply necessary updates to protect against unauthorized exploitation.

Affected Version(s)

Wiser for KNX Wiser for KNX, V2.1.0 and prior

Wiser for KNX homeLYnk V2.0.1 and prior

Wiser for KNX spaceLYnk V2.1.0 and prior

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.