« Volver al listado

CVE-2023-42770

Estado: ModificadaCrítica (9.8)—

Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-42770",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-42770",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-12-09T05:05:23.134802Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Red Lion Controls",
          "product": "ST-IPm-8460",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.202"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "ST-IPm-6350",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-mIPm-135-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-mIPm-245-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-IPm2m-213-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Red Lion Controls",
          "product": "VT-IPm2m-113-D",
          "versions": [
            {
              "status": "affected",
              "version": "4.9.114"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-21T01:15:07.100",
  "references": [
    {
      "url": "https://https://support.redlion.net/hc/en-us/articles/19339209248269-RLCSIM-2023-05-Authentication-Bypass-and-Remote-Code-Execution",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://https://support.redlion.net/hc/en-us/articles/19339209248269-RLCSIM-2023-05-Authentication-Bypass-and-Remote-Code-Execution",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-288"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nRed Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.\n\n"
    },
    {
      "lang": "es",
      "value": "Red Lion SixTRAK y VersaTRAK Series RTU con usuarios autenticados habilitados (UDR-A), cualquier mensaje Sixnet UDR enfrentará un desafío de autenticación a través de UDP/IP. Cuando se recibe el mismo mensaje a través de TCP/IP, la RTU simplemente aceptará el mensaje sin desafío de autenticación."
    }
  ],
  "lastModified": "2026-06-17T06:24:28.063",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:st-ipm-6350_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "685CF00F-7FEC-4DC9-BBAF-4B83A51ABB53"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:st-ipm-6350:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FAB3B611-15F5-4921-A8C8-89B0D0A00AA2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:st-ipm-8460_firmware:6.0.202:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "491A31DC-903F-467B-815E-0AC7FA349147"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:st-ipm-8460:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5CAC9FF0-38FA-4C34-8082-C592CB02F0AC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-mipm-135-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "618F8D7E-6154-461F-BBCF-A69BFDE5CA5E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-mipm-135-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6BEFDF88-C073-4336-AD11-7707260A105E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-mipm-245-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2473CC87-6ADB-4159-AA7C-4112C913678C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-mipm-245-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4E26FEC2-6332-4F68-8FF5-3A941E91A105"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-ipm2m-213-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FF18734-7D47-4DC5-A0C2-4F39298EFF26"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-ipm2m-213-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C184211-9CF8-499B-B8D4-EBC58134FF6F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redlioncontrols:vt-ipm2m-113-d_firmware:4.9.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A231928-AF55-4697-B0A3-C92ECEAF523B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:redlioncontrols:vt-ipm2m-113-d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D2F4E6FF-1358-4105-AEEC-C7AD34D00EA6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}