7.2
CVE-2021-22735
- EPSS 0.85%
- Veröffentlicht 26.05.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:50:33
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Spacelynk Firmware Version <= 2.6.0
Schneider-electric ≫ Homelynk Firmware Version <= 2.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.85% | 0.727 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.