---
cve: "CVE-2023-46383"
severity: "LOW"
cvss: 3.1
epss: "1.4%"
vendor: "n/a"
kev: false
exploited: false
published: "2023-11-30 23:15:07"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T09:29:16+02:00"
---

# CVE-2023-46383

> 3.1 LOW · 🧪 PoC

## Beschreibung

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

## Referenzen

- <https://seclists.org/fulldisclosure/2023/Nov/6>
- <https://packetstormsecurity.com/files/175951/Loytec-LINX-Configurator-7.4.10-Insecure-Transit-Cleartext-Secrets.html>
- <https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01>
- <http://seclists.org/fulldisclosure/2023/Nov/6>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-46383) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
