Vulnerability Description
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Homelynk Controller Lss100100 Firmware | < 1.5.0 |
| Schneider-Electric | Homelynk Controller Lss100100 | - |
Related Weaknesses (CWE)
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-052-02Vendor Advisory
- http://www.securityfocus.com/bid/97585Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-019-01AThird Party AdvisoryUS Government Resource
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-052-02Vendor Advisory
- http://www.securityfocus.com/bid/97585Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-019-01AThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2017-7689?
CVE-2017-7689 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
How severe is CVE-2017-7689?
CVE-2017-7689 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7689?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Homelynk Controller Lss100100 Firmware, Schneider-Electric Homelynk Controller Lss100100.