« Volver al listado

CVE-2023-40151

Estado: ModificadaCrítica (9.8)—

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-40151",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-40151",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-12-09T05:05:22.191314Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Red Lion Controls",
          "product": "ST-IPm-8460",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.202"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "ST-IPm-6350",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-mIPm-135-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-mIPm-245-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-IPm2m-213-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-IPm2m-113-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-21T00:15:06.953",
  "references": [
    {
      "url": "https://support.redlion.net/hc/en-us/articles/19339209248269-RLCSIM-2023-05-Authentication-Bypass-and-Remote-Code-Execution",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://support.redlion.net/hc/en-us/articles/19339209248269-RLCSIM-2023-05-Authentication-Bypass-and-Remote-Code-Execution",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-749"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\nWhen user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "Cuando la autenticación de usuario no está habilitada, el shell puede ejecutar comandos con los privilegios más altos. Red Lion SixTRAK y VersaTRAK Series RTU con usuarios autenticados habilitados (UDR-A), cualquier mensaje Sixnet UDR enfrentará un desafío de autenticación a través de UDP/IP. Cuando llega el mismo mensaje a través de TCP/IP, la RTU simplemente aceptará el mensaje sin desafío de autenticación."
    }
  ],
  "lastModified": "2026-06-17T06:16:25.970",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:st-ipm-6350_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "685CF00F-7FEC-4DC9-BBAF-4B83A51ABB53"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:st-ipm-6350:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FAB3B611-15F5-4921-A8C8-89B0D0A00AA2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:st-ipm-8460_firmware:6.0.202:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "491A31DC-903F-467B-815E-0AC7FA349147"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:st-ipm-8460:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5CAC9FF0-38FA-4C34-8082-C592CB02F0AC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-mipm-135-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "618F8D7E-6154-461F-BBCF-A69BFDE5CA5E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-mipm-135-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6BEFDF88-C073-4336-AD11-7707260A105E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-mipm-245-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2473CC87-6ADB-4159-AA7C-4112C913678C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-mipm-245-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4E26FEC2-6332-4F68-8FF5-3A941E91A105"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-ipm2m-213-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FF18734-7D47-4DC5-A0C2-4F39298EFF26"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-ipm2m-213-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C184211-9CF8-499B-B8D4-EBC58134FF6F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-ipm2m-113-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A231928-AF55-4697-B0A3-C92ECEAF523B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-ipm2m-113-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D2F4E6FF-1358-4105-AEEC-C7AD34D00EA6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}