PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-46384 LOYTEC electronics GmbH CVE debrief

LOYTEC electronics GmbH LINX Configurator 7.4.10 contains a vulnerability where credentials are stored in cleartext, enabling remote attackers to disclose the admin password and bypass authentication. The issue affects multiple LOYTEC LINX series devices and the L-INX Configurator software. CISA published advisory ICSA-24-247-01 on September 3, 2024, documenting this vulnerability with a CVSS 3.1 score of 7.5 (HIGH). LOYTEC recommends updating affected products to version 8.2.8 and notes that a patch for CVE-2023-46384 will be published in LINX Configurator.

Vendor
LOYTEC electronics GmbH
Product
L-INX Configurator
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-03
Original CVE updated
2024-09-03
Advisory published
2024-09-03
Advisory updated
2024-09-03

Who should care

Organizations operating LOYTEC LINX series building automation or industrial control systems, particularly those with remote management capabilities enabled. Critical infrastructure operators and facilities management teams using LOYTEC devices for HVAC, lighting, or access control systems should prioritize remediation.

Technical summary

The vulnerability stems from insecure permissions in LOYTEC LINX Configurator 7.4.10, specifically the cleartext storage of administrative credentials. Remote attackers can exploit this weakness to extract the admin password without authentication, enabling complete administrative access to affected LOYTEC LINX series devices. The attack vector is network-based with low complexity and no required privileges or user interaction.

Defensive priority

HIGH

Recommended defensive actions

  • Update affected LOYTEC products to version 8.2.8 per vendor guidance
  • Apply LINX Configurator patch when released by LOYTEC
  • Audit credential storage configurations across LOYTEC LINX deployments
  • Implement network segmentation to limit remote access to LOYTEC management interfaces
  • Monitor for unauthorized authentication attempts on affected systems

Evidence notes

CISA advisory ICSA-24-247-01 confirms cleartext credential storage in LINX Configurator 7.4.10 allows remote admin password disclosure and authentication bypass. Affected products include LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, and L-INX Configurator. Vendor remediation guidance specifies update to version 8.2.8 with patch forthcoming.

Official resources

2024-09-03