PT-2023-29991 · Loytec · Loytec Linx-151+6

·

CVE-2023-46382

·

Publicado

2023-11-04

·

Atualizado

2024-09-19

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LOYTEC LINX-151 (affected versions not specified) LOYTEC LINX-212 version 6.2.4 LOYTEC LVIS-3ME12-A1 version 6.2.2 LOYTEC LIOB-586 version 6.2.3 LOYTEC LIOB-580 V2 (affected versions not specified) LOYTEC LIOB-588 (affected versions not specified) L-INX Configurator devices (all versions)
Description The issue concerns the use of cleartext HTTP for login by various LOYTEC devices. This means that login credentials are transmitted without encryption, potentially allowing them to be intercepted by an attacker.
Recommendations For LOYTEC LINX-151, consider disabling cleartext HTTP login until a secure alternative is implemented. For LOYTEC LINX-212 version 6.2.4, restrict login to use only encrypted connections. For LOYTEC LVIS-3ME12-A1 version 6.2.2, avoid using cleartext HTTP for login. For LOYTEC LIOB-586 version 6.2.3, use a secure connection for login. For LOYTEC LIOB-580 V2, implement a secure login mechanism. For LOYTEC LIOB-588, disable cleartext HTTP login. For L-INX Configurator devices, use encrypted connections for login.

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46382

Produtos afetados

Linx Configurator
Loytec Linx-151
Loytec Linx-212
Loytec Liob-580
Loytec Liob-586
Loytec Liob-588
Loytec Lvis-3Me12-A1