6.5
CVE-2021-22740
- EPSS 0.33%
- Veröffentlicht 26.05.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:50:34
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Spacelynk Firmware Version <= 2.6.0
Schneider-electric ≫ Homelynk Firmware Version <= 2.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.33% | 0.525 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.