Red Lion Controls N
Reporting by CISA ICS AdvisoriesRead the original at cisa.gov
Executive Summary
Facts Only
* Vulnerabilities affect Red Lion Controls N-Tron 700 Series devices with Firmware <= 3.11.0 and Bootloader <= 2.0.6.1.
* Exploitation allows administrative access, enabling viewing, editing, and uploading configuration files.
* A malicious user can cause the switch to reboot by navigating to a specific URL on the device.
* The reboot action is scriptable from the local machine to cause continuous rebooting.
* Vulnerabilities include Use of Hard-coded Credentials (CWE-798), Storing Passwords in a Recoverable Format (CWE-257), and Missing Authentication for Critical Function (CWE-306).
* Relevant CVSS scores range from 3.1/6 (MEDIUM) to 4.0/9.3 (CRITICAL).
* All affected products have the same stated remediation steps: upgrade to firmware version 3.11.1 or greater, configure/disable SNMP communities, and disable web GUI access.
Full Take
From the original · CISA ICS Advisories
Tron 700 Series Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files.Read the full story at cisa.gov
Sentinel — Human
The text appears to be a structured compilation of technical vulnerability data and official mitigation advice, strongly indicative of a source derived from a vendor advisory or security bulletin.
