QID 590765

Date Published: 2022-05-06

QID 590765: Schneider Electric spaceLYnk Wiser For KNX and fellerLYnk Multiple Vulnerabilities (SEVD-2022-039-04)

Affected Products
spaceLYnk V2.6.2 and prior
Wiser for KNX (formerly homeLYnk) V2.6.2 and prior
fellerLYnk V2.6.2 and prior

Successful exploitation of this vulnerability could Cross-Site Request Forgery (CSRF), Missing Authentication, rate limit, or Stored Cross-Site Scripting (XSS) attack which could result in exfiltrated data and unauthorized access.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 8.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2022-039-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590765

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-039-04 URL Logo www.se.com/ww/en/download/document/SEVD-2022-039-04/