First published: Wed May 26 2021(Updated: )
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Spacelynk Firmware | <=2.6.0 | |
Schneider-electric Spacelynk | ||
Schneider-electric Homelynk Firmware | <=2.6.0 | |
Schneider-electric Homelynk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22733 is an Improper Privilege Management vulnerability that exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior, which could cause shell access when unauthorized code is loaded into the system folder.
The severity of CVE-2021-22733 is high (7.8).
The Schneider-electric Spacelynk Firmware versions up to and including 2.6.0 and Schneider-electric Homelynk Firmware versions up to and including 2.6.0 are affected by CVE-2021-22733.
CVE-2021-22733 can be exploited by loading unauthorized code into the system folder, which could result in shell access.
Schneider-electric Spacelynk and Homelynk are not vulnerable to CVE-2021-22733, except for the specific firmware versions mentioned.