Insecure Permissions in Loytec LINX Configurator Affects Device Configuration
CVE-2023-46385

7.5HIGH

Key Information:

Vendor

Loytec

Vendor
CVE Published:
30 November 2023

What is CVE-2023-46385?

LOYTEC electronics GmbH's LINX Configurator is susceptible to a vulnerability that exposes admin credentials through unencrypted URL parameters. This flaw allows remote attackers to intercept these credentials and potentially gain unauthorized access to the full configuration of Loytec devices. Proper protections against insecure permissions and credential transmission are critical to safeguarding device integrity.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.