Red Lion Controls Sixnet RTU Exposed Dangerous Method Or Function
CVE-2023-40151
10CRITICAL
What is CVE-2023-40151?
The vulnerability arises from a lack of user authentication for command execution in Red Lion SixTRAK and VersaTRAK Series RTUs. When authentication is not enforced, these devices can accept UDP/IP messages without a proper security challenge, allowing potentially malicious actors to execute commands with elevated privileges. This flaw highlights the risk of unsecured device communications and the necessity for robust authentication mechanisms to safeguard industrial control systems.
Affected Version(s)
ST-IPm-6350 4.9.114
ST-IPm-8460 6.0.202
VT-IPm2m-113-D 4.9.114
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nitsan Litov of Claroty Research - Team82 reported these vulnerabilities to CISA.
