The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be change…
Authorized users may install a maliciously modified package file when updating the device via the web user interface. The user may inadvertently use …
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resourc…
A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could re…
An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authenti…
The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on t…
The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to s…
The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform acti…
The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by lurin…
Red Lion HMI panels allow remote attackers to cause a denial of service (software exception) via an HTTP POST request to a long URI that does not exi…