Incorrect Access Control in LOYTEC Devices Affects Sensitive Configuration Data
CVE-2023-46389

7.5HIGH

Key Information:

Vendor

Loytec

Vendor
CVE Published:
30 November 2023

What is CVE-2023-46389?

LOYTEC electronics GmbH's LINX-212 and LINX-151 devices are susceptible to an Incorrect Access Control vulnerability through the 'registry.xml' file. This flaw opens the door for remote attackers to exploit the device and potentially disclose sensitive configuration information, posing risks to the security and integrity of the affected systems. It is critical for users and administrators of these devices to be aware of this vulnerability and take necessary precautions to mitigate any potential threats.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.