PT-2023-25639 · Loxone · Loxone Miniserver Go Gen.2

·

CVE-2023-36623

·

Published

2023-07-05

·

Updated

2023-07-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Loxone Miniserver Go Gen.2 versions prior to 14.2
Description The issue allows a local user to calculate the root password and escalate privileges due to the root password being calculated using hard-coded secrets and the MAC address.
Recommendations For versions prior to 14.2, update to version 14.2 or later to resolve the issue. As a temporary workaround, consider restricting local access to the Miniserver to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-36623

Affected Products

Loxone Miniserver Go Gen.2