CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 10.0. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-40151
Severity
CRITICAL
CVSS
10
EPSS
1.15%
Original NVD Description
When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.
Related CVEs
Other vulnerabilities affecting the same vendor(s)