Insufficient Entropy Vulnerability in LOYTEC LVIS-3ME Web Interface
CVE-2017-13992

8.1HIGH

Key Information:

Vendor

Loytec

Vendor
CVE Published:
5 October 2017

What is CVE-2017-13992?

An insufficient entropy vulnerability exists in the web interface of LOYTEC LVIS-3ME versions prior to 6.2.0. This flaw arises from the application’s reliance on weak random number generation for its authentication mechanism. Exploiting this vulnerability could lead to unauthorized access and potential remote code execution, posing significant security risks. Users of affected versions are encouraged to upgrade to mitigate these risks.

Affected Version(s)

LOYTEC LVIS-3ME LOYTEC LVIS-3ME

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.