Skip to main content

Vendor archive

loytec CVEs

Beta · best-effort

18 CVEs tagged to vendor loytec2 Critical, 14 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-46385

Published Nov 30, 2023

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so i…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46384

Published Nov 30, 2023

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46383

Published Nov 30, 2023

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote atta…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-13998

Published Oct 5, 2017

An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13994

Published Oct 5, 2017

A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occ…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13992

Published Oct 5, 2017

An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interfa…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1