PT-2021-7735 · Spacelynk+1 · Spacelynk+1

Published

2021-05-11

·

Updated

2021-06-04

·

CVE-2021-22738

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions homeLYnk (Wiser For KNX) versions prior to V2.60 spaceLYnk versions prior to V2.60
Description The issue is related to the use of a broken or risky cryptographic algorithm, which could allow an attacker to gain unauthorized access to protected information after discovering credentials through a brute force attack. This could potentially lead to unauthorized access when credentials are compromised.
Recommendations For homeLYnk (Wiser For KNX) versions prior to V2.60, update to a version that uses a secure cryptographic algorithm to prevent unauthorized access. For spaceLYnk versions prior to V2.60, update to a version that uses a secure cryptographic algorithm to prevent unauthorized access. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02126
CVE-2021-22738

Affected Products

Homelynk
Spacelynk