CVE-2023-5719 is a critical vulnerability affecting Red Lion Crimson 3.2, DA50A, and DA70A products. It allows an administrator to inadvertently create truncated, easily compromised passwords if a percent (%) character is used in the Crimson 3.2 configuration tool. This vulnerability has a CVSS score of 9.8 (Critical), indicating a high potential for compromise with low attack complexity and no user interaction required, leading to full confidentiality, integrity, and availability impact. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= v3.2.0053.18CPE match | cpe:2.3:a:redlion:crimson:*:*:*:*:*:*:*:* | ||
< 3.2CPE matchmatch criteria | cpe:2.3:a:redlion:crimson:*:*:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:a:redlion:crimson:3.2:build_3.2.0008.0:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:a:redlion:crimson:3.2:build_3.2.0014.0:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:a:redlion:crimson:3.2:build_3.2.0015.0:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.