CVE-2019-10990

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
23/09/2019
Last modified:
01/03/2023

Description

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redlion:crimson:*:*:*:*:*:*:*:* 3.0 (including)
cpe:2.3:a:redlion:crimson:*:*:*:*:*:*:*:* 3.1 (including) 3112.00 (excluding)


References to Advisories, Solutions, and Tools