CVE-2019-6832: High severity wiser for knx vulnerability
Published Sep 17, 2019
·Updated
A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known as homeLYnk), which could cause loss of control when an attacker bypasses the authentication.
Affected Software
4 affected components
Schneider-electric Wiser For Knx Firmware<2.4.0
Schneider-electric Lss100100
Schneider-electric Spacelynk Firmware<2.4.0
Schneider-electric Lss100200
Event History
Sep 17, 2019
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this authentication vulnerability in spaceLYnk and Wiser for KNX?
The vulnerability ID for this authentication vulnerability in spaceLYnk and Wiser for KNX is CVE-2019-6832.
2
What is the severity of CVE-2019-6832?
CVE-2019-6832 has a severity rating of 8.3 (High).
3
Which software versions are affected by CVE-2019-6832?
All versions before 2.4.0 of spaceLYnk and Wiser for KNX are affected by CVE-2019-6832.
4
How can an attacker exploit this authentication vulnerability?
An attacker can exploit this authentication vulnerability by bypassing the authentication, which could cause a loss of control.
5
Is there a fix available for CVE-2019-6832?
Yes, a fix is available. Users should update to version 2.4.0 or later of spaceLYnk and Wiser for KNX.