CVE-2017-7689

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:homelynk_controller_lss100100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:homelynk_controller_lss100100:-:*:*:*:*:*:*:*

History

02 Feb 2022, 02:13

Type Values Removed Values Added
First Time Schneider-electric homelynk Controller Lss100100 Firmware
CPE cpe:2.3:o:schneider_electric:homelynk_controller_lss100100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:homelynk_controller_lss100100_firmware:*:*:*:*:*:*:*:*

31 Jan 2022, 20:16

Type Values Removed Values Added
First Time Schneider-electric
Schneider-electric homelynk Controller Lss100100
CPE cpe:2.3:h:schneider_electric:homelynk_controller_lss100100:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:homelynk_controller_lss100100:-:*:*:*:*:*:*:*
References (MISC) https://ics-cert.us-cert.gov/advisories/ICSA-17-019-01A - Third Party Advisory, US Government Resource (MISC) https://ics-cert.us-cert.gov/advisories/ICSA-17-019-01A - US Government Resource, Third Party Advisory

Information

Published : 2017-04-11 21:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-7689

Mitre link : CVE-2017-7689

CVE.ORG link : CVE-2017-7689


JSON object : View

Products Affected

schneider-electric

  • homelynk_controller_lss100100_firmware
  • homelynk_controller_lss100100
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')