CVE-2022-22809
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
09/02/2022
Last modified:
22/02/2023
Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:schneider-electric:spacelynk_firmware:*:*:*:*:*:*:*:* | 2.6.2 (including) | |
| cpe:2.3:h:schneider-electric:spacelynk:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:*:*:*:*:*:*:*:* | 2.6.2 (including) | |
| cpe:2.3:h:schneider-electric:wiser_for_knx:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:fellerlynk_firmware:*:*:*:*:*:*:*:* | 2.6.2 (including) | |
| cpe:2.3:h:schneider-electric:fellerlynk:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



