Cross-Site Request Forgery in Schneider Electric SpaceLYnk and Wiser for KNX
CVE-2022-22811
8.1HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
Summary
A Cross-Site Request Forgery (CSRF) vulnerability in Schneider Electric's spaceLYnk, Wiser for KNX, and fellerLYnk products allows malicious actors to trick users into executing unintended commands. By luring users to a fraudulent website, an attacker could manipulate configurations and settings without direct interaction with the systems, leading to potential system misconfigurations and security lapses.
Affected Version(s)
spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved