CVE-2021-22733: High severity schneider-electric spacelynk firmware vulnerability
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22733?
CVE-2021-22733 is an Improper Privilege Management vulnerability that exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior, which could cause shell access when unauthorized code is loaded into the system folder.
What is the severity of CVE-2021-22733?
The severity of CVE-2021-22733 is high (7.8).
What software is affected by CVE-2021-22733?
The Schneider-electric Spacelynk Firmware versions up to and including 2.6.0 and Schneider-electric Homelynk Firmware versions up to and including 2.6.0 are affected by CVE-2021-22733.
How can CVE-2021-22733 be exploited?
CVE-2021-22733 can be exploited by loading unauthorized code into the system folder, which could result in shell access.
Is Schneider-electric Spacelynk and Homelynk vulnerable to CVE-2021-22733?
Schneider-electric Spacelynk and Homelynk are not vulnerable to CVE-2021-22733, except for the specific firmware versions mentioned.