Vulnerability Description
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Loytec | Linx-212 Firmware | 6.2.4 |
| Loytec | Linx-212 | - |
| Loytec | Lvis-3Me12-A1 Firmware | 6.2.2 |
| Loytec | Lvis-3Me12-A1 | - |
| Loytec | Liob-586 Firmware | 6.2.3 |
| Loytec | Liob-586 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/175646/LOYTEC-Electronics-Insecure-Transit-Third Party Advisory
- https://seclists.org/fulldisclosure/2023/Nov/0Mailing ListThird Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01
- https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-
- http://packetstormsecurity.com/files/175646/LOYTEC-Electronics-Insecure-Transit-Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Nov/0
- https://seclists.org/fulldisclosure/2023/Nov/0Mailing ListThird Party Advisory
- https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-
FAQ
What is CVE-2023-46382?
CVE-2023-46382 is a vulnerability with a CVSS score of 7.5 (HIGH). LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.
How severe is CVE-2023-46382?
CVE-2023-46382 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46382?
Check the references section above for vendor advisories and patch information. Affected products include: Loytec Linx-212 Firmware, Loytec Linx-212, Loytec Lvis-3Me12-A1 Firmware, Loytec Lvis-3Me12-A1, Loytec Liob-586 Firmware.