Vulnerability Details CVE-2021-22806
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-22806
-
cpe:2.3:h:schneider-electric:fellerlynk:-
-
cpe:2.3:h:schneider-electric:spacelynk:-
-
cpe:2.3:h:schneider-electric:wiser_for_knx:-
-
cpe:2.3:o:schneider-electric:fellerlynk_firmware:2.6.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:-
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.0.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.1.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.1.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.2.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.0.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.0.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.1.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.1.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.3.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.4.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.5.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.5.1
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:-
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.1.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.1.1
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.3.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.4.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.5.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.5.1