CVE-2019-10990: Medium severity Redlion Crimson vulnerability
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10990?
CVE-2019-10990 is a vulnerability in Red Lion Controls Crimson software that allows an attacker to access configuration files.
What is the severity of CVE-2019-10990?
The severity of CVE-2019-10990 is medium with a CVSS score of 6.5.
How does CVE-2019-10990 work?
CVE-2019-10990 uses a hard-coded password to encrypt files in transit and at rest, which can be exploited by attackers to gain unauthorized access to configuration files.
What software versions are affected by CVE-2019-10990?
Red Lion Controls Crimson versions 3.0 and prior, as well as version 3.1 prior to release 3112.00, are affected by CVE-2019-10990.
Is there a fix for CVE-2019-10990?
At the moment, there is no known fix or patch for CVE-2019-10990. Red Lion Controls may release a security update in the future.