First published: Wed Feb 09 2022(Updated: )
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Spacelynk Firmware | <=2.6.2 | |
Schneider-electric Spacelynk | ||
Schneider-electric Wiser For Knx Firmware | <=2.6.2 | |
Schneider-electric Wiser For Knx | ||
Schneider-electric Fellerlynk Firmware | <=2.6.2 | |
Schneider-electric Fellerlynk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22810 is a vulnerability that allows an attacker to manipulate the admin after numerous attempts at guessing credentials.
The affected products are spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), and fellerlynk (V2.6.2 and prior).
CVE-2022-22810 has a severity level of critical (9.8).
An attacker can exploit CVE-2022-22810 by making numerous attempts at guessing credentials to manipulate the admin.
Yes, the fix for CVE-2022-22810 is to update the affected products to versions later than V2.6.2.