Vulnerabilities > Redlion > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-17 | CVE-2023-34412 | Cross-site Scripting vulnerability in multiple products A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS). | 4.8 |
2022-11-17 | CVE-2022-3090 | Path Traversal vulnerability in Redlion Crimson Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal. | 5.3 |
2022-04-20 | CVE-2022-26516 | Insufficient Verification of Data Authenticity vulnerability in Redlion Da50N Firmware Authorized users may install a maliciously modified package file when updating the device via the web user interface. | 6.8 |
2022-04-20 | CVE-2022-27179 | Insufficiently Protected Credentials vulnerability in Redlion Da50N Firmware A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. | 4.0 |
2021-01-06 | CVE-2020-27283 | Improper Resource Shutdown or Release vulnerability in Redlion Crimson 3.1 An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations. | 5.0 |
2021-01-06 | CVE-2020-27285 | Missing Authentication for Critical Function vulnerability in Redlion Crimson 3.1 The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication. | 6.4 |
2019-09-23 | CVE-2019-10990 | Use of Hard-coded Credentials vulnerability in Redlion Crimson Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files. | 6.5 |