Schneider-electric
Schneider-electric Spacelynk Firmware: vulnerabilidades y CVE
Schneider-electric Spacelynk Firmware tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-22806 | Alta (7.5) | 0.95% | — | 11 feb 2022 | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior),… |
| CVE-2022-22812 | Media (6.1) | 0.60% | — | 9 feb 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary… |
| CVE-2022-22811 | Alta (8.1) | 0.41% | — | 9 feb 2022 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit… |
| CVE-2022-22810 | Crítica (9.8) | 1.1% | — | 9 feb 2022 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk… |
| CVE-2022-22809 | Media (5.3) | 0.79% | — | 9 feb 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch… |
| CVE-2021-22740 | Media (6.5) | 0.80% | — | 26 may 2021 | Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded. |
| CVE-2021-22739 | Media (5.9) | 0.82% | — | 26 may 2021 | Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured. |
| CVE-2021-22738 | Crítica (9.8) | 0.63% | — | 26 may 2021 | Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force… |
| CVE-2021-22737 | Crítica (9.8) | 0.95% | — | 26 may 2021 | Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack. |
| CVE-2021-22736 | Alta (7.5) | 1.1% | — | 26 may 2021 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized… |
| CVE-2021-22735 | Alta (7.2) | 1.0% | — | 26 may 2021 | Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device. |
| CVE-2021-22734 | Alta (7.2) | 1.0% | — | 26 may 2021 | Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code. |
| CVE-2021-22733 | Alta (7.8) | 0.21% | — | 26 may 2021 | Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder. |
| CVE-2021-22732 | Alta (7.8) | 0.26% | — | 26 may 2021 | Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server. |
| CVE-2020-7525 | Alta (7.5) | 1.5% | — | 31 ago 2020 | Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute… |
| CVE-2019-6832 | Alta (8.3) | 1.5% | — | 17 sept 2019 | A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known as homeLYnk), which could cause loss of control when an attacker… |
| CVE-2018-7779 | Alta (7.5) | 1.4% | — | 3 jul 2018 | In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access. |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon M340 Bmxp342000 Firmware · 25Modicon Quantum Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Easergy T300 Firmware · 24