CVE-2021-22806: High severity schneider-electric spacelynk firmware vulnerability
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22806?
CVE-2021-22806 is a vulnerability known as CWE-669: Incorrect Resource Transfer Between Spheres, which could lead to data exfiltration and unauthorized access when accessing a malicious website.
What products are affected by CVE-2021-22806?
The affected products are spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), and fellerLYnk (V2.6.1 and prior).
What is the severity of CVE-2021-22806?
The severity of CVE-2021-22806 is high, with a severity value of 7.5.
How can CVE-2021-22806 be exploited?
CVE-2021-22806 can be exploited by accessing a malicious website, which could lead to data exfiltration and unauthorized access.
How can I mitigate CVE-2021-22806?
To mitigate CVE-2021-22806, it is recommended to update the affected products to versions higher than V2.6.1.