Weak FTP Access in Schneider Electric Wiser and Related Products
CVE-2018-7779
7.5HIGH
Summary
Schneider Electric products, including Wiser for KNX, homeLYnk, and spaceLYnk, are impacted by a vulnerability that allows unauthorized access due to weak and unprotected FTP configurations. This flaw can enable attackers to exploit the FTP access, potentially leading to compromised system integrity and confidentiality. Users are advised to review security measures and apply necessary updates to protect against unauthorized exploitation.
Affected Version(s)
Wiser for KNX Wiser for KNX, V2.1.0 and prior
Wiser for KNX homeLYnk V2.0.1 and prior
Wiser for KNX spaceLYnk V2.1.0 and prior
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved