PatchSiren cyber security CVE debrief
CVE-2023-46380 LOYTEC electronics GmbH CVE debrief
LOYTEC Electronics LINX Series devices transmit password-change requests over unencrypted HTTP, exposing credentials to network eavesdropping. The vulnerability affects multiple product lines including LINX-212, LVIS-3ME12-A1, and LIOB-586 with specific firmware versions 6.2.4, 6.2.2, and 6.2.3 respectively. CISA published this advisory on September 3, 2024. The vendor has released firmware version 8.2.8 to address this issue.
- Vendor
- LOYTEC electronics GmbH
- Product
- LINX-151
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-03
- Original CVE updated
- 2024-09-03
- Advisory published
- 2024-09-03
- Advisory updated
- 2024-09-03
Who should care
Organizations operating LOYTEC building automation and industrial control systems, including facility managers, OT security teams, and critical infrastructure operators deploying LINX-212, LVIS-3ME12-A1, LIOB-586, and related product lines.
Technical summary
Affected LOYTEC devices in the LINX series transmit password-change requests over unencrypted HTTP rather than HTTPS. This allows network adversaries with passive monitoring capability to capture administrative credentials during password change operations. The vulnerability is network-accessible without authentication (AV:N, PR:N) and requires no user interaction. Successful exploitation results in high confidentiality impact through credential compromise, though integrity and availability impacts are not directly affected per the CVSS vector.
Defensive priority
HIGH
Recommended defensive actions
- Update affected LOYTEC devices to firmware version 8.2.8 or later
- Disable HTTP on affected LOYTEC devices per the vendor's security hardening guide
- Implement network segmentation to isolate affected building automation devices from untrusted networks
- Monitor network traffic for unencrypted HTTP sessions to affected device management interfaces
- Review and rotate credentials that may have been transmitted over cleartext HTTP
- Apply defense-in-depth controls per CISA ICS recommended practices for industrial control systems
Evidence notes
The CISA CSAF advisory ICSA-24-247-01 explicitly states that affected LOYTEC devices send password-change requests via cleartext HTTP. The advisory lists seven affected products: LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, and L-INX Configurator. Specific firmware versions mentioned are LINX-212 firmware 6.2.4, LVIS-3ME12-A1 firmware 6.2.2, and LIOB-586 firmware 6.2.3. The CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yields a base score of 7.5 (HIGH severity).
Sources and references
Verified primary and authoritative sources
-
CVE-2023-46380 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-46380
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-46380 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-46380
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-247-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.