VendorsRedlioncrimsonall versions
Vulnerabilities

Redlion Red Lion Crimson

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-5719
Red Lion Crimson Improper Neutralization of Null Byte or NUL Character
Published 2023-11-06 · Modified
9.8EPSS 0.005
CVE-2020-27285
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.
Published 2021-01-06 · Modified
9.1EPSS 0.009
CVE-2020-27279
A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).
Published 2021-01-06 · Modified
7.8EPSS 0.017
CVE-2019-10984
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that causes the program to mishandle pointers.
Published 2019-09-23 · Modified
7.8EPSS 0.010
CVE-2019-10996
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that can reference memory after it has been freed.
Published 2019-09-23 · Modified
7.8EPSS 0.010
CVE-2019-10978
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that operates outside of the designated memory area.
Published 2019-09-23 · Modified
7.8EPSS 0.009
CVE-2022-3090
Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal. When attempting to open a file using a specific path, the user's password hash is sent to an arbitrary host. This could allow an attacker to obtain user credential hashes.
Published 2022-11-17 · Modified
7.5EPSS 0.006
CVE-2019-10990
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.
Published 2019-09-23 · Modified
6.5EPSS 0.013
CVE-2020-27283
An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.
Published 2021-01-06 · Modified
5.3EPSS 0.009