PT-2023-29990 · Loytec · Loytec Liob-586+7
Chizuru Toyama
·
Published
2023-11-04
·
Updated
2024-09-19
·
CVE-2023-46381
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
LOYTEC LINX-151 (affected versions not specified)
LOYTEC LINX-212 version 6.2.4
LOYTEC LVIS-3ME12-A1 version 6.2.2
LOYTEC LIOB-586 version 6.2.3
LOYTEC LIOB-580 V2 (affected versions not specified)
LOYTEC LIOB-588 (affected versions not specified)
L-INX Configurator devices (all versions)
Description
The issue concerns a lack of authentication for the preinstalled version of LWEB-802 via an
lweb802 pre/ URI. An unauthenticated attacker can edit any project, create a new project, and control its GUI.Recommendations
For LOYTEC LINX-151, restrict access to the
lweb802 pre/ URI until a patch is available.
For LOYTEC LINX-212 version 6.2.4, consider disabling the LWEB-802 service until a fix is provided.
For LOYTEC LVIS-3ME12-A1 version 6.2.2, avoid using the lweb802 pre/ URI in production environments until the issue is resolved.
For LOYTEC LIOB-586 version 6.2.3, limit access to the LWEB-802 interface to minimize the risk of exploitation.
For LOYTEC LIOB-580 V2, LIOB-588, and L-INX Configurator devices, restrict access to the lweb802 pre/ URI and LWEB-802 service until a patch or fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linx Configurator
Loytec Linx-151
Loytec Linx-212
Loytec Liob-580
Loytec Liob-586
Loytec Liob-588
Loytec Lvis-3Me12-A1
Lweb-802