QID 590518

Date Published: 2021-10-14

QID 590518: Schneider Electric homeLYnk Controller (Update A) Multiple Vulnerabilities (ICSA-17-019-01A)

AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following products:
homeLYnk Controller, LSS100100, all versions prior to V1.5.0

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker may be able to exploit this vulnerability to cause execution of java script code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-17-019-01A for affected packages and patching details.

    Vendor References

    CVEs related to QID 590518

    Software Advisories
    Advisory ID Software Component Link
    ICSA-17-019-01A URL Logo www.us-cert.gov/ics/advisories/ICSA-17-019-01A