← Back to browse · API

CVE-2023-40151

Severity
CRITICAL
CVSS
10.0
EPSS
0.01149
Risk score
40.4
CISA KEV
No
PoC
No
Published
2023-11-21
Modified
2026-02-25
First seen
2026-08-07
Aliases
EUVD-2023-44758, GHSA-HXG4-C72J-73RF
Products
Red Lion Controls:ST-IPm-6350 4.9.114, Red Lion Controls:ST-IPm-8460 6.0.202, Red Lion Controls:VT-IPm2m-113-D 4.9.114, Red Lion Controls:VT-IPm2m-213-D 4.9.114, Red Lion Controls:VT-mIPm-135-D 4.9.114, Red Lion Controls:VT-mIPm-245-D 4.9.114
Sources
euvd EUVD-2023-44758

Description

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

References