Roaring Access: Exploiting a Pre-Auth Root RCE on Sixnet RTUs
ID: 1bdb7715-425e-58e9-b6b4-830f95586246
STIX ID: report--1bdb7715-425e-58e9-b6b4-830f95586246
Feed Name: Claroty Team82
Threat Score
Team82 discloses two critical vulnerabilities (CVE-2023-42770) in Red Lion Sixnet RTUs (SixTRAK and VersaTRAK) where the Sixnet Universal protocol's TCP handling bypasses UDP-based authentication on port 1594, allowing unauthenticated remote execution of shell commands as root; Red Lion and CISA have published advisories and patches, and organizations are urged to apply updates and block TCP access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
