Cross-Site Request Forgery in Schneider Electric SpaceLYnk and Wiser for KNX
CVE-2022-22811

8.1HIGH

Summary

A Cross-Site Request Forgery (CSRF) vulnerability in Schneider Electric's spaceLYnk, Wiser for KNX, and fellerLYnk products allows malicious actors to trick users into executing unintended commands. By luring users to a fraudulent website, an attacker could manipulate configurations and settings without direct interaction with the systems, leading to potential system misconfigurations and security lapses.

Affected Version(s)

spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.