CVE-2022-22810: Critical severity schneider-electric spacelynk firmware vulnerability
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-22810?
CVE-2022-22810 is a vulnerability that allows an attacker to manipulate the admin after numerous attempts at guessing credentials.
Which products are affected by CVE-2022-22810?
The affected products are spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), and fellerlynk (V2.6.2 and prior).
What is the severity of CVE-2022-22810?
CVE-2022-22810 has a severity level of critical (9.8).
How can an attacker exploit CVE-2022-22810?
An attacker can exploit CVE-2022-22810 by making numerous attempts at guessing credentials to manipulate the admin.
Is there a fix for CVE-2022-22810?
Yes, the fix for CVE-2022-22810 is to update the affected products to versions later than V2.6.2.