---
cve: "CVE-2023-46388"
severity: "LOW"
cvss: 3.1
epss: "1.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2023-11-30 23:15:07"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T16:40:01+02:00"
---

# CVE-2023-46388

> 3.1 LOW · 🧪 PoC

## Beschreibung

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

## Referenzen

- <http://seclists.org/fulldisclosure/2023/Nov/7>
- <http://packetstormsecurity.com/files/175952/Loytec-L-INX-Automation-Servers-Information-Disclosure-Cleartext-Secrets.html>
- <https://www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-24-247-01>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-46388) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
