CVE-2023-42770
moderate-risk
Published 2023-11-21
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.
Do I need to act?
-
0.16% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
10
CVSS 10.0/10
Critical
NETWORK
/ LOW complexity
Affected Products (6)
St-Ipm-6350 Firmware
St-Ipm-8460 Firmware
Vt-Mipm-135-D Firmware
Vt-Mipm-245-D Firmware
Vt-Ipm2M-213-D Firmware
Vt-Ipm2M-113-D Firmware
Affected Vendors
References (4)
Third Party Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01
Third Party Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01
47
/ 100
moderate-risk
Severity
33/34 · Critical
Exploitability
1/34 · Minimal
Exposure
13/34 · Low