CVE-2021-22737: Critical severity schneider-electric spacelynk firmware vulnerability
Published May 26, 2021
·Updated
Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.
Affected Software
4 affected components
Schneider-electric Spacelynk Firmware<=2.6.0
Schneider-electric Spacelynk
Schneider-electric Homelynk Firmware<=2.6.0
Schneider-electric Homelynk
Event History
May 26, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22737?
CVE-2021-22737 is a vulnerability that exists in homeLYnk and spaceLYnk V2.60 and prior, allowing unauthorized access through brute force attacks.
2
How severe is CVE-2021-22737?
CVE-2021-22737 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
3
Which software versions are affected by CVE-2021-22737?
CVE-2021-22737 affects homeLYnk and spaceLYnk versions up to and including 2.6.0.
4
How can unauthorized access be gained through CVE-2021-22737?
Unauthorized access can be gained by discovering credentials after a brute force attack.
5
How can I protect against CVE-2021-22737?
To protect against CVE-2021-22737, it is recommended to apply the latest firmware updates provided by Schneider-electric.