Vulnerability: Lack of Authentication Challenge for Sixnet UDR Messages over TCP/IP in Red Lion SixTRAK and VersaTRAK Series RTUs

Vulnerability: Lack of Authentication Challenge for Sixnet UDR Messages over TCP/IP in Red Lion SixTRAK and VersaTRAK Series RTUs

CVE-2023-42770 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.

Learn more about our User Device Pen Test.