Vulnerabilities > Redlion

DATE CVE VULNERABILITY TITLE RISK
2023-11-06 CVE-2023-5719 Unspecified vulnerability in Redlion Crimson
The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device.
network
low complexity
redlion
critical
9.8
2022-11-17 CVE-2022-3090 Unspecified vulnerability in Redlion Crimson
Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal.
network
low complexity
redlion
5.3
2022-04-20 CVE-2022-1039 Weak Password Requirements vulnerability in Redlion Da50N Firmware
The weak password on the web user interface can be exploited via HTTP or HTTPS.
network
low complexity
redlion CWE-521
critical
9.8
2022-04-20 CVE-2022-26516 Unspecified vulnerability in Redlion Da50N Firmware
Authorized users may install a maliciously modified package file when updating the device via the web user interface.
local
low complexity
redlion
7.8
2022-04-20 CVE-2022-27179 Unspecified vulnerability in Redlion Da50N Firmware
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource.
network
low complexity
redlion
6.5
2021-01-06 CVE-2020-27283 Improper Resource Shutdown or Release vulnerability in Redlion Crimson 3.1
An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.
network
low complexity
redlion CWE-404
5.3
2021-01-06 CVE-2020-27279 NULL Pointer Dereference vulnerability in Redlion Crimson 3.1
A NULL pointer deference vulnerability has been identified in the protocol converter.
network
low complexity
redlion CWE-476
7.5
2021-01-06 CVE-2020-27285 Missing Authentication for Critical Function vulnerability in Redlion Crimson 3.1
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.
network
low complexity
redlion CWE-306
critical
9.1
2020-09-01 CVE-2020-16210 Unspecified vulnerability in Redlion N-Tron 702-W Firmware and N-Tron 702M12-W Firmware
The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions).
network
low complexity
redlion
critical
9.0
2020-09-01 CVE-2020-16208 Unspecified vulnerability in Redlion N-Tron 702-W Firmware and N-Tron 702M12-W Firmware
The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions).
network
low complexity
redlion
8.8