PT-2023-29990 · Loytec · Loytec Liob-586+7

Chizuru Toyama

·

Published

2023-11-04

·

Updated

2024-09-19

·

CVE-2023-46381

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions LOYTEC LINX-151 (affected versions not specified) LOYTEC LINX-212 version 6.2.4 LOYTEC LVIS-3ME12-A1 version 6.2.2 LOYTEC LIOB-586 version 6.2.3 LOYTEC LIOB-580 V2 (affected versions not specified) LOYTEC LIOB-588 (affected versions not specified) L-INX Configurator devices (all versions)
Description The issue concerns a lack of authentication for the preinstalled version of LWEB-802 via an lweb802 pre/ URI. An unauthenticated attacker can edit any project, create a new project, and control its GUI.
Recommendations For LOYTEC LINX-151, restrict access to the lweb802 pre/ URI until a patch is available. For LOYTEC LINX-212 version 6.2.4, consider disabling the LWEB-802 service until a fix is provided. For LOYTEC LVIS-3ME12-A1 version 6.2.2, avoid using the lweb802 pre/ URI in production environments until the issue is resolved. For LOYTEC LIOB-586 version 6.2.3, limit access to the LWEB-802 interface to minimize the risk of exploitation. For LOYTEC LIOB-580 V2, LIOB-588, and L-INX Configurator devices, restrict access to the lweb802 pre/ URI and LWEB-802 service until a patch or fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-46381

Affected Products

Linx Configurator
Loytec Linx-151
Loytec Linx-212
Loytec Liob-580
Loytec Liob-586
Loytec Liob-588
Loytec Lvis-3Me12-A1
Lweb-802