6.5
CVE-2021-22740
- EPSS 0.33%
- Published 26.05.2021 20:15:09
- Last modified 21.11.2024 05:50:34
- Source cybersecurity@se.com
- Teams watchlist Login
- Open Login
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Spacelynk Firmware Version <= 2.6.0
Schneider-electric ≫ Homelynk Firmware Version <= 2.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.33% | 0.525 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.