Vulnerability: Unauthenticated Command Execution with Highest Privileges in Red Lion SixTRAK and VersaTRAK Series RTUs

Vulnerability: Unauthenticated Command Execution with Highest Privileges in Red Lion SixTRAK and VersaTRAK Series RTUs

CVE-2023-40151 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

Learn more about our User Device Pen Test.