Database/Control plane, storage & DevOps
Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-bounds
Impact
An out-of-bounds read in BACnet packet parsing lets an unauthenticated attacker crash the main control process and reboot the device with a single malformed TimeSynchronization message - and BACnet TimeSynchronization is a broadcast service, so one packet can take out every Loytec device on the segment at once. Loytec controllers and gateways are the BACnet/LonWorks integration layer in a lot of European-designed and mixed-vendor datacenters, sitting between the IP supervisory network and the field bus that runs air handling. Rebooting them all simultaneously severs supervisory control of cooling for as long as the attacker keeps sending, which against 40-140 kW GPU racks is a straightforward path to thermal shutdown across a hall. The companion issues in the same disclosure set (unauthenticated stored XSS in the OPC XML-DA statistics page, a PAM misconfiguration allowing authentication as an unintended uid, and an SNMP agent loop-condition bug) mean the same devices also offer credential-theft and persistence paths, not just DoS.
Who can reach it
Unauthenticated, remote, over BACnet on the facility network - and via broadcast, so it does not even need to know device addresses. The SNMP and web issues are likewise reachable from anywhere on that segment. Anyone who can put a frame on the building VLAN can do this.
What to do
Firmware update from Loytec above 8.4.18 for the device family, plus LWEB-802 5.0.8+ for the management side. This is a per-device firmware flash across every gateway and controller, done by the controls integrator, with each device offline during the flash - a maintenance window on live cooling. Because a broadcast packet is the trigger, the compensating control has to actually block broadcast BACnet from untrusted hosts, which usually means putting the BACnet segment on its own VLAN with no untrusted hosts on it at all rather than trying to filter by address. Disable the SNMP agent and the OPC XML-DA interface if you are not using them.
References
Related entries
- Netty: OpenSSL client path silently skips TLS hostname verification on Java 25+CVE-2026-62243 · Netty io.netty:netty-handler (SslProvider.OPENSSL client-side hostname verification)High
- Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposesCVE-2026-6445 · Pure Storage FlashArray Purity (data path information exposure)High
- SeaweedFS S3 API: raw OIDC JWT bypasses IAM role trust policy and grants that role's bucket accessCVE-2026-77298 · SeaweedFS S3 API (direct OIDC bearer token to IAM role mapping)High
- OpenNebula: one.vm.exec skips the permission check, letting any user run commands in other tenants' VMsCVE-2026-84165 · OpenNebula (one.vm.exec API authorization)High
- GitLab: stored XSS through merge request diff paths runs script in another user's sessionCVE-2026-84739 · GitLab CE/EE merge request diff viewer (path component sanitization)High
- HPE iLO3/4/5: Remote unauthenticated denial of service against the management controllerCVE-2018-7093 · HPE iLO3/4/5High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.