Vulnerabilities > Redlion > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-20 CVE-2022-26516 Unspecified vulnerability in Redlion Da50N Firmware
Authorized users may install a maliciously modified package file when updating the device via the web user interface.
local
low complexity
redlion
7.8
2021-01-06 CVE-2020-27279 NULL Pointer Dereference vulnerability in Redlion Crimson 3.1
A NULL pointer deference vulnerability has been identified in the protocol converter.
network
low complexity
redlion CWE-476
7.5
2020-09-01 CVE-2020-16208 Unspecified vulnerability in Redlion N-Tron 702-W Firmware and N-Tron 702M12-W Firmware
The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions).
network
low complexity
redlion
8.8
2019-09-23 CVE-2019-10996 Use After Free vulnerability in Redlion Crimson
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that can reference memory after it has been freed.
local
low complexity
redlion CWE-416
7.8
2019-09-23 CVE-2019-10984 Unspecified vulnerability in Redlion Crimson
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that causes the program to mishandle pointers.
local
low complexity
redlion
7.8
2019-09-23 CVE-2019-10978 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Redlion Crimson
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that operates outside of the designated memory area.
local
low complexity
redlion CWE-119
7.8
2017-12-30 CVE-2017-14855 Unspecified vulnerability in Redlion HMI Panel Firmware 2.41
Red Lion HMI panels allow remote attackers to cause a denial of service (software exception) via an HTTP POST request to a long URI that does not exist, as demonstrated by version HMI 2.41 PLC 2.42.
network
low complexity
redlion
8.6
2017-11-20 CVE-2017-16544 Code Injection vulnerability in multiple products
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal.
network
low complexity
busybox debian vmware redlion canonical CWE-94
8.8