Missing Authentication Vulnerability in Schneider Electric's spaceLYnk and Wiser for KNX
CVE-2022-22809
5.3MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
Summary
A vulnerability exists in Schneider Electric's products where the lack of authentication allows unauthorized users to modify sensitive touch configurations. This security flaw poses a risk to the integrity of device settings in spaceLYnk, Wiser for KNX, and fellerLYnk prior to version 2.6.2. An attacker exploiting this vulnerability could potentially alter configurations without appropriate credentials, compromising the security framework of these systems.
Affected Version(s)
spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved