PatchSiren cyber security CVE debrief
CVE-2023-46384 LOYTEC electronics GmbH CVE debrief
LOYTEC electronics GmbH LINX Configurator 7.4.10 contains a vulnerability where credentials are stored in cleartext, enabling remote attackers to disclose the admin password and bypass authentication. The issue affects multiple LOYTEC LINX series devices and the L-INX Configurator software. CISA published advisory ICSA-24-247-01 on September 3, 2024, documenting this vulnerability with a CVSS 3.1 score of 7.5 (HIGH). LOYTEC recommends updating affected products to version 8.2.8 and notes that a patch for CVE-2023-46384 will be published in LINX Configurator.
- Vendor
- LOYTEC electronics GmbH
- Product
- L-INX Configurator
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-03
- Original CVE updated
- 2024-09-03
- Advisory published
- 2024-09-03
- Advisory updated
- 2024-09-03
Who should care
Organizations operating LOYTEC LINX series building automation or industrial control systems, particularly those with remote management capabilities enabled. Critical infrastructure operators and facilities management teams using LOYTEC devices for HVAC, lighting, or access control systems should prioritize remediation.
Technical summary
The vulnerability stems from insecure permissions in LOYTEC LINX Configurator 7.4.10, specifically the cleartext storage of administrative credentials. Remote attackers can exploit this weakness to extract the admin password without authentication, enabling complete administrative access to affected LOYTEC LINX series devices. The attack vector is network-based with low complexity and no required privileges or user interaction.
Defensive priority
HIGH
Recommended defensive actions
- Update affected LOYTEC products to version 8.2.8 per vendor guidance
- Apply LINX Configurator patch when released by LOYTEC
- Audit credential storage configurations across LOYTEC LINX deployments
- Implement network segmentation to limit remote access to LOYTEC management interfaces
- Monitor for unauthorized authentication attempts on affected systems
Evidence notes
CISA advisory ICSA-24-247-01 confirms cleartext credential storage in LINX Configurator 7.4.10 allows remote admin password disclosure and authentication bypass. Affected products include LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, and L-INX Configurator. Vendor remediation guidance specifies update to version 8.2.8 with patch forthcoming.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-46384 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-46384
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-46384 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-46384
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-247-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.