Skip to main content

Vendor archive

redlion CVEs

Beta · best-effort

20 CVEs tagged to vendor redlion6 Critical, 10 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-3090

Published Nov 17, 2022

Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27179

Published Apr 20, 2022

A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26516

Published Apr 20, 2022

Authorized users may install a maliciously modified package file when updating the device via the web user interface. The user may inadvertently use a package file obtained from a…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1039

Published Apr 20, 2022

The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27283

Published Jan 6, 2021

An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27279

Published Jan 6, 2021

A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimso…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27285

Published Jan 6, 2021

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10996

Published Sep 23, 2019

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially craft…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10990

Published Sep 23, 2019

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10984

Published Sep 23, 2019

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially craft…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10978

Published Sep 23, 2019

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially craft…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-14855

Published Dec 30, 2017

Red Lion HMI panels allow remote attackers to cause a denial of service (software exception) via an HTTP POST request to a long URI that does not exist, as demonstrated by version…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1