Insecure Authentication in Loytec LINX Configurator Affects All Versions
CVE-2023-46383

7.5HIGH

Key Information:

Vendor

Loytec

Vendor
CVE Published:
30 November 2023

What is CVE-2023-46383?

The LINX Configurator by LOYTEC electronics GmbH, used for configuring devices, employs HTTP Basic Authentication, which encodes credentials in base64 without encryption. This design flaw exposes usernames and passwords in cleartext during transmission, enabling remote attackers to intercept these credentials and gain unauthorized control over device configurations. Such vulnerabilities can lead to severe compromises in security for devices reliant on this configurator.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.