PatchSiren cyber security CVE debrief
CVE-2023-46382 LOYTEC electronics GmbH CVE debrief
LOYTEC Electronics LINX Series devices transmit authentication credentials in cleartext HTTP, exposing sensitive information to network eavesdropping. The vulnerability affects multiple product lines including LINX-212, LVIS-3ME12-A1, and LIOB-586 with specific firmware versions 6.2.4, 6.2.2, and 6.2.3 respectively. CISA published this advisory on September 3, 2024. The CVSS 3.1 score of 7.5 reflects high confidentiality impact with network accessibility and low attack complexity. No known exploitation in ransomware campaigns has been reported.
- Vendor
- LOYTEC electronics GmbH
- Product
- LINX-151
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-03
- Original CVE updated
- 2024-09-03
- Advisory published
- 2024-09-03
- Advisory updated
- 2024-09-03
Who should care
Organizations operating LOYTEC LINX series building automation and industrial control devices, particularly in facilities management, smart building deployments, and critical infrastructure environments where credential compromise could enable unauthorized system access. Security teams responsible for OT/ICS network security and network administrators managing segmented industrial control networks should prioritize assessment.
Technical summary
Affected LOYTEC electronics GmbH devices transmit login credentials over unencrypted HTTP connections. The vulnerability exists in LINX-212 firmware 6.2.4, LVIS-3ME12-A1 firmware 6.2.2, and LIOB-586 firmware 6.2.3. Network attackers can intercept authentication traffic without authentication or user interaction. The CVSS 3.1 score of 7.5 (HIGH) reflects confidentiality impact through passive network monitoring. Vendor remediation requires firmware update to version 8.2.8 and HTTP service disablement per security hardening guidance.
Defensive priority
HIGH
Recommended defensive actions
- Update affected LOYTEC devices to firmware version 8.2.8 per vendor recommendation.
- Disable HTTP on affected LOYTEC devices and enforce HTTPS-only access as recommended in LOYTEC's security hardening guide.
- Implement network segmentation to isolate affected ICS devices from untrusted networks.
- Monitor network traffic for unencrypted HTTP authentication sessions to affected device models.
- Review and apply CISA ICS recommended practices for defense-in-depth strategies.
Evidence notes
The vulnerability description is sourced from CISA's CSAF advisory ICSA-24-247-01, which identifies specific firmware versions affected: LINX-212 firmware 6.2.4, LVIS-3ME12-A1 firmware 6.2.2, and LIOB-586 firmware 6.2.3. The advisory was published on 2024-09-03 with initial revision. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N confirms network-based attack with no privileges required.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-46382 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-46382
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-46382 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-46382
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-247-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.