Incorrect Access Control in Loytec LINX Devices
CVE-2023-46387

7.5HIGH

Key Information:

Vendor

Loytec

Vendor
CVE Published:
30 November 2023

What is CVE-2023-46387?

LOYTEC electronics GmbH's LINX-212 and LINX-151 devices are susceptible to an Incorrect Access Control vulnerability via the dpal_config.zml file. This issue permits remote attackers to potentially exploit sensitive information regarding the data point configuration of Loytec devices, which could lead to unauthorized access and exposure of critical data. It is crucial for users and administrators to assess the security measures in place and seek remediation to safeguard their systems from such vulnerabilities.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.