CVE-2023-46385

HIGH

LOYTEC electronics GmbH LINX Configurator - Privilege Escalation

Title source: llm
STIX 2.1

Description

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

Scores

CVSS v3 7.5
EPSS 0.0076
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (1)
loytec/l-inx_configurator 7.4.10
Published Nov 30, 2023
Tracked Since Feb 18, 2026