CyberRota Analysis
AI-GeneratedThe vulnerability exists in the PAM configuration of various Loytec devices, allowing local attackers to gain unauthorized root access by authenticating as the uid=0 account without a password. This could lead to complete system compromise, enabling attackers to execute arbitrary commands with elevated privileges. Organizations using affected Loytec products should prioritize addressing this vulnerability to mitigate potential security risks.
Original NVD Description
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.