The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric spaceLYnk V2.6.2 and prior
- Schneider Electric Wiser for KNX (formerly homeLYnk) V2.6.2 and prior
- Schneider Electric fellerLYnk V2.6.2 and prior
- Summary
- A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations.
- Remediation
- Version 2.7.0 of the spaceLYnk product includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/LSS100200/spacelynk-logiccontroller/ A reboot is needed after installation.
