CVE-2023-46385
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 30, 2023
Updated: Dec 14, 2023
CWE ID 319
Summary
CVE-2023-46385 is a vulnerability affecting LOYTEC electronics GmbH LINX Configurator version 7.4.10. This issue involves insecure permissions, allowing unauthorized access to admin credentials. The vulnerability arises from the passing of admin credentials as URL parameters without encryption, making them susceptible to interception by remote attackers. Successful exploitation of this flaw grants attackers the ability to steal passwords and ultimately obtain full control of Loytec device configurations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share