loytec CVE 脆弱性と CVE 一覧(18)

製品(CPE): — CVE 件数: 18

loytec 脆弱性概要

loytec 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには パス処理の欠陥 and vendor risk cross-site scripting があり、vendor surface production workloads and vendor surface software deployment の利用場面で ファイル上書き and vendor impact session compromise などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 118 / 18 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2023-46389 LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration. [email protected] 7.5 0.40% 2023-11-30 2024-11-21
CVE-2023-46388 LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication. [email protected] 7.5 0.13% 2023-11-30 2024-11-21
CVE-2023-46387 LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration. [email protected] 7.5 0.40% 2023-11-30 2024-11-21
CVE-2023-46386 LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication. [email protected] 7.5 0.13% 2023-11-30 2024-11-21
CVE-2023-46385 LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration. [email protected] 7.5 0.18% 2023-11-30 2025-11-04
CVE-2023-46384 LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device. [email protected] 7.5 0.17% 2023-11-30 2025-11-04
CVE-2023-46383 LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration. [email protected] 7.5 0.19% 2023-11-30 2025-11-04
CVE-2023-46382 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login. [email protected] 7.5 0.09% 2023-11-04 2025-11-04
CVE-2023-46381 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI. [email protected] 8.2 0.14% 2023-11-04 2025-11-04
CVE-2023-46380 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP. [email protected] 7.5 0.09% 2023-11-04 2025-11-04
CVE-2018-14918 LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. [email protected] 7.5 67.62% 2019-06-28 2024-11-21
CVE-2018-14916 LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion. [email protected] 9.1 67.29% 2019-06-28 2024-11-21
CVE-2018-14919 LOYTEC LGATE-902 6.3.2 devices allow XSS. [email protected] 6.1 1.69% 2019-06-28 2024-11-21
CVE-2017-13998 An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access. [email protected] 7.5 0.45% 2017-10-05 2026-05-13
CVE-2017-13996 A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attacker to create or modify files or execute arbitrary code. [email protected] 8.8 1.83% 2017-10-05 2026-05-13
CVE-2017-13994 A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticated user of the web interface is tricked into clicking a malicious link. [email protected] 6.1 0.26% 2017-10-05 2026-05-13
CVE-2017-13992 An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication mechanism, which could allow remote code execution. [email protected] 8.1 6.27% 2017-10-05 2026-05-13
CVE-2015-7906 LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors. [email protected] 10.0 0.60% 2015-12-21 2026-05-06
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence