CVE-2023-46385

L

OYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

Configurations

Configuration 1 (hide)

cpe:2.3:a:loytec:l-inx_configurator:7.4.10:*:*:*:*:*:*:*

History

04 Nov 2025, 20:17

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2023/Nov/6 -

21 Nov 2024, 08:28

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/175951/Loytec-LINX-Configurator-7.4.10-Insecure-Transit-Cleartext-Secrets.html - Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/175951/Loytec-LINX-Configurator-7.4.10-Insecure-Transit-Cleartext-Secrets.html - Third Party Advisory, VDB Entry
References () https://seclists.org/fulldisclosure/2023/Nov/6 - Mailing List, Third Party Advisory () https://seclists.org/fulldisclosure/2023/Nov/6 - Mailing List, Third Party Advisory
References () https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/ - () https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/ -

20 Sep 2024, 17:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01 -
Summary (en) LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration. (en) LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

Information

Published : 2023-11-30 23:15

Updated : 2025-11-04 20:17


NVD link : CVE-2023-46385

Mitre link : CVE-2023-46385

CVE.ORG link : CVE-2023-46385


JSON object : View

Products Affected
CWE
CWE-319

Cleartext Transmission of Sensitive Information