QID 590596

Date Published: 2022-04-12

QID 590596: Schneider Electric spaceLYnk,Wiser For KNX, and fellerLYnk Incorrect Resource Transfer Between Spheres vulnerability (SEVD-2021-285-01)

SpaceLYnk is a centralized solution that reduces energy and maintenance costs, increases comfort and flexibility and simplifies building management. Wiser for KNX products are personalized energy efficiency solutions, offering a complete system based on open protocols: KNX, Modbus, BACnet and IP. FellerLYnk offers more flexibility in visualization and trend recording as well as functions such as presence simulation or time switches that the end customer can easily manage.

AFFECTED PRODUCTS
spaceLYnk V2.6.1 and prior
Wiser for KNX V2.6.1 and prior fellerLYnk V2.6.1 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow a cross-origin resource sharing attack, which could result in exfiltrated data and unauthorized access.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to update to latest version SEVD-2021-285-01 for affected packages.

    Vendor References

    CVEs related to QID 590596

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2021-285-01 URL Logo www.se.com/ww/en/download/document/SEVD-2021-285-01/