Red Lion Controls Sixnet RTU Authentication Bypass Using An Alternative Path Or Channel
CVE-2023-42770
10CRITICAL
What is CVE-2023-42770?
An authentication bypass vulnerability exists in Red Lion SixTRAK and VersaTRAK Series RTUs when messages are processed over TCP/IP. Specifically, while these devices enforce an authentication challenge for UDP/IP messages, they fail to do so when receiving the same messages via TCP/IP. This design oversight allows unauthenticated users to send commands to the RTUs, potentially compromising the integrity and security of the systems relying on these devices.
Affected Version(s)
ST-IPm-6350 4.9.114
ST-IPm-8460 6.0.202
VT-IPm2m-113-D 4.9.114
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nitsan Litov of Claroty Research - Team82 reported these vulnerabilities to CISA.
