First published: Fri Feb 11 2022(Updated: )
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Spacelynk Firmware | <=2.6.1 | |
Schneider-electric Spacelynk | ||
Schneider-electric Wiser For Knx Firmware | <=2.6.1 | |
Schneider-electric Wiser For Knx | ||
Schneider-electric Fellerlynk Firmware | <=2.6.1 | |
Schneider-electric Fellerlynk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22806 is a vulnerability known as CWE-669: Incorrect Resource Transfer Between Spheres, which could lead to data exfiltration and unauthorized access when accessing a malicious website.
The affected products are spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), and fellerLYnk (V2.6.1 and prior).
The severity of CVE-2021-22806 is high, with a severity value of 7.5.
CVE-2021-22806 can be exploited by accessing a malicious website, which could lead to data exfiltration and unauthorized access.
To mitigate CVE-2021-22806, it is recommended to update the affected products to versions higher than V2.6.1.