PT-2023-25640 · Loxone · Loxone Miniserver Go Gen.2

Tobias Jäger

·

Published

2023-07-05

·

Updated

2023-07-12

·

CVE-2023-36624

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Loxone Miniserver Go Gen.2 through 14.0.3.28
Description The issue allows an authenticated operating system user to escalate privileges via the Sudo configuration, enabling the elevated execution of binaries without a password requirement.
Recommendations For versions through 14.0.3.28, consider restricting the Sudo configuration to prevent privilege escalation until a patch is available. As a temporary workaround, review and limit the execution of binaries that can be run without a password requirement to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-36624

Affected Products

Loxone Miniserver Go Gen.2