PatchSiren cyber security CVE debrief
CVE-2023-46384 LOYTEC electronics GmbH CVE debrief
LOYTEC electronics GmbH LINX Configurator 7.4.10 contains a vulnerability where credentials are stored in cleartext, enabling remote attackers to disclose the admin password and bypass authentication. The issue affects multiple LOYTEC LINX series devices and the L-INX Configurator software. CISA published advisory ICSA-24-247-01 on September 3, 2024, documenting this vulnerability with a CVSS 3.1 score of 7.5 (HIGH). LOYTEC recommends updating affected products to version 8.2.8 and notes that a patch for CVE-2023-46384 will be published in LINX Configurator.
- Vendor
- LOYTEC electronics GmbH
- Product
- L-INX Configurator
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-03
- Original CVE updated
- 2024-09-03
- Advisory published
- 2024-09-03
- Advisory updated
- 2024-09-03
Who should care
Organizations operating LOYTEC LINX series building automation or industrial control systems, particularly those with remote management capabilities enabled. Critical infrastructure operators and facilities management teams using LOYTEC devices for HVAC, lighting, or access control systems should prioritize remediation.
Technical summary
The vulnerability stems from insecure permissions in LOYTEC LINX Configurator 7.4.10, specifically the cleartext storage of administrative credentials. Remote attackers can exploit this weakness to extract the admin password without authentication, enabling complete administrative access to affected LOYTEC LINX series devices. The attack vector is network-based with low complexity and no required privileges or user interaction.
Defensive priority
HIGH
Recommended defensive actions
- Update affected LOYTEC products to version 8.2.8 per vendor guidance
- Apply LINX Configurator patch when released by LOYTEC
- Audit credential storage configurations across LOYTEC LINX deployments
- Implement network segmentation to limit remote access to LOYTEC management interfaces
- Monitor for unauthorized authentication attempts on affected systems
Evidence notes
CISA advisory ICSA-24-247-01 confirms cleartext credential storage in LINX Configurator 7.4.10 allows remote admin password disclosure and authentication bypass. Affected products include LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, and L-INX Configurator. Vendor remediation guidance specifies update to version 8.2.8 with patch forthcoming.
Official resources
-
CVE-2023-46384 CVE record
CVE.org
-
CVE-2023-46384 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-09-03