Path Traversal Vulnerability in Red Lion Controls Crimson Software
CVE-2022-3090
7.5HIGH
What is CVE-2022-3090?
Red Lion Controls Crimson software is exposed to a path traversal vulnerability that allows unauthorized access to sensitive user information. When a user attempts to open a file using a specific path, the application inadvertently sends the user's password hash to an arbitrary external host. This mismanagement of file paths can lead to attackers obtaining user credential hashes, thereby jeopardizing system and data security.
Affected Version(s)
Crimson 3.0 All versions <= 707.000
Crimson 3.1 All versions <= 3126.001
Crimson 3.2 All versions <= 3.2.0044.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dragos reported this vulnerability to Red Lion Controls, who reported this vulnerability to CISA
