Missing Authentication Vulnerability in Schneider Electric's spaceLYnk and Wiser for KNX
CVE-2022-22809

5.3MEDIUM

Summary

A vulnerability exists in Schneider Electric's products where the lack of authentication allows unauthorized users to modify sensitive touch configurations. This security flaw poses a risk to the integrity of device settings in spaceLYnk, Wiser for KNX, and fellerLYnk prior to version 2.6.2. An attacker exploiting this vulnerability could potentially alter configurations without appropriate credentials, compromising the security framework of these systems.

Affected Version(s)

spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.