CVE-2017-7689: Command Injection
Published Apr 11, 2017
·Updated
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
Affected Software
4 affected components
Schneider-electric Homelynk Controller Lss100100 Firmware<1.5.0
Schneider-electric Homelynk Controller Lss100100
All of the following
Schneider-electric Homelynk Controller Lss100100 Firmware<1.5.0
Schneider-electric Homelynk Controller Lss100100
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric homeLYnk Controllerto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Apr 11, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7689?
CVE-2017-7689 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2017-7689?
To fix CVE-2017-7689, upgrade the Schneider Electric homeLYnk Controller firmware to version 1.5.0 or later.
3
Which versions are affected by CVE-2017-7689?
All versions of Schneider Electric homeLYnk Controller before 1.5.0 are affected by CVE-2017-7689.
4
What type of vulnerability is CVE-2017-7689?
CVE-2017-7689 is a command injection vulnerability.
5
Who is the vendor for CVE-2017-7689?
The vendor for CVE-2017-7689 is Schneider Electric.