Incorrect Resource Transfer Vulnerability in Schneider Electric Products
CVE-2021-22806

7.5HIGH

Summary

A vulnerability exists in Schneider Electric products that allows for potential data exfiltration and unauthorized access through malicious websites. This risk primarily affects versions V2.6.1 and earlier of spaceLYnk, Wiser for KNX, and fellerLYnk. Users should be aware of the implications of accessing untrusted websites, as it could lead to compromised security and breach of confidential information.

Affected Version(s)

spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior) spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.