PT-2023-29991 · Loytec · Loytec Linx-151+6
Chizuru Toyama
·
Published
2023-11-04
·
Updated
2024-09-19
·
CVE-2023-46382
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LOYTEC LINX-151 (affected versions not specified)
LOYTEC LINX-212 version 6.2.4
LOYTEC LVIS-3ME12-A1 version 6.2.2
LOYTEC LIOB-586 version 6.2.3
LOYTEC LIOB-580 V2 (affected versions not specified)
LOYTEC LIOB-588 (affected versions not specified)
L-INX Configurator devices (all versions)
Description
The issue concerns the use of cleartext HTTP for login by various LOYTEC devices. This means that login credentials are transmitted without encryption, potentially allowing them to be intercepted by an attacker.
Recommendations
For LOYTEC LINX-151, consider disabling cleartext HTTP login until a secure alternative is implemented.
For LOYTEC LINX-212 version 6.2.4, restrict login to use only encrypted connections.
For LOYTEC LVIS-3ME12-A1 version 6.2.2, avoid using cleartext HTTP for login.
For LOYTEC LIOB-586 version 6.2.3, use a secure connection for login.
For LOYTEC LIOB-580 V2, implement a secure login mechanism.
For LOYTEC LIOB-588, disable cleartext HTTP login.
For L-INX Configurator devices, use encrypted connections for login.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linx Configurator
Loytec Linx-151
Loytec Linx-212
Loytec Liob-580
Loytec Liob-586
Loytec Liob-588
Loytec Lvis-3Me12-A1