Authentication Bypass in LOYTEC LINX Configurator Devices
CVE-2023-46381
8.2HIGH
What is CVE-2023-46381?
Several models of LOYTEC devices, including the LINX-151, LINX-212, and others, exhibit a critical vulnerability due to a lack of authentication for the LWEB-802 version accessible through the lweb802_pre/ URI. This allows unauthenticated attackers to edit, delete, or create new projects, giving them control over the graphical user interface (GUI) of these devices. Such vulnerabilities can lead to unauthorized alterations, potentially compromising the integrity of building automation systems and controlling essential functionalities without detection.
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
