QID 591013
Date Published: 2022-08-26
QID 591013: Schneider Electric homeLYnk Controller Vulnerability (SEVD-2017-011-01)
AFFECTED PRODUCTS
homeLYnk Controller, LSS100100, all versions prior to V1.5.0
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
The homeLYnk controller is susceptible to a Cross-Site Scripting attack on its 404 page. User inputs can be manipulated to cause execution of java script code.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2017-011-01 for affected packages and patching details.
Vendor References
- SEVD-2017-011-01 -
www.se.com/il/en/download/document/SEVD-2017-011-01/
CVEs related to QID 591013
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2017-011-01 |
|