CVE-2023-40151

CRITICAL

Red Lion SixTRAK and VersaTRAK Series - Privilege Escalation

Title source: llm
STIX 2.1

Description

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

Scores

CVSS v3 10.0
EPSS 0.0037
EPSS Percentile 58.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-749
Status published
Products (6)
redlioncontrols/st-ipm-6350_firmware 4.9.114
redlioncontrols/st-ipm-8460_firmware 6.0.202
redlioncontrols/vt-ipm2m-113-d_firmware 4.9.114
redlioncontrols/vt-ipm2m-213-d_firmware 4.9.114
redlioncontrols/vt-mipm-135-d_firmware 4.9.114
redlioncontrols/vt-mipm-245-d_firmware 4.9.114
Published Nov 21, 2023
Tracked Since Feb 18, 2026