CVE-2023-46386

L

OYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:loytec:linx-212_firmware:6.2.4:*:*:*:*:*:*:*
cpe:2.3:h:loytec:linx-212:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:loytec:linx-151_firmware:7.2.4:*:*:*:*:*:*:*
cpe:2.3:h:loytec:linx-151:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:28

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/175952/Loytec-L-INX-Automation-Servers-Information-Disclosure-Cleartext-Secrets.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/175952/Loytec-L-INX-Automation-Servers-Information-Disclosure-Cleartext-Secrets.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2023/Nov/7 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2023/Nov/7 - Mailing List, Third Party Advisory
References () https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/ - () https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/ -

20 Sep 2024, 17:15

Type Values Removed Values Added
Summary (en) LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication. (en) LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01 -

Information

Published : 2023-11-30 23:15

Updated : 2024-11-21 08:28


NVD link : CVE-2023-46386

Mitre link : CVE-2023-46386

CVE.ORG link : CVE-2023-46386


JSON object : View

CWE
CWE-312

Cleartext Storage of Sensitive Information