Red Lion Controls N-Tron 700 Series

Summary

Multiple vulnerabilities have been discovered in Red Lion Controls N-Tron 700 Series devices, allowing potential attackers to gain administrative access, view/edit configuration files, and cause device reboots. Successful exploitation could lead to unauthorized control and disruption of critical infrastructure. Affected versions include firmware up to 3.11.0 and bootloader up to 2.0.6.1.

IFF Assessment

FOE

The discovery of multiple critical vulnerabilities that allow for administrative access and system disruption is detrimental to defenders.

Severity

8.3 High

The CVSS score of 8.3 indicates a High severity. This is likely due to factors such as the ability to gain administrative access, modify configurations, and cause denial of service (reboots), coupled with potential ease of exploitability in certain network environments.

Defender Context

Defenders need to be aware of these vulnerabilities affecting industrial control systems (ICS) and ensure their Red Lion Controls N-Tron 700 Series devices are updated to firmware version 3.11.1 or greater. The ability for attackers to gain administrative access and cause reboots poses a significant risk to operational continuity and security.

Read Full Story →