Red Lion Controls develops industrial networking and interface products for operational technology environments, with particular focus on the ST-IPM and VT-IPM gateway and communication device families. The observed vulnerability pattern centers on authentication and access-control deficiencies, including authentication bypass through alternate channels, exposure of dangerous methods or functions, and missing authentication for critical operations, reflecting the security-sensitive nature of networked industrial control components. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redlioncontrols over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42770CRITICAL
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message | Nov 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-40151CRITICAL
When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled ( | Nov 21, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redlioncontrols.
Media articles that mention a CVE ID that affects a product developed by Redlioncontrols — matched by CVE ID, not by vendor name.