Executive Summary
In October 2025, two critical vulnerabilities (CVE-2023-40151 and CVE-2023-42770) were publicly disclosed in Red Lion Sixnet RTU devices, which are widely used for industrial automation and critical infrastructure. Both flaws received a CVSS 10.0 rating, underscoring their exploitability and impact. Attackers exploiting these vulnerabilities could achieve remote code execution with the highest privileges, granting them full control over affected devices. These RTUs are often deployed in energy, utilities, and manufacturing, raising concerns about the potential for business disruption, safety risks, and further attacks via compromised operational technology networks.
This incident is particularly relevant as it highlights how legacy and specialized industrial control systems remain a prime target for threat actors leveraging zero-day vulnerabilities. The convergence of IT and OT, combined with growing regulatory scrutiny and an uptick in supply chain exposures, means that organizations must refocus on asset visibility and patch management for embedded and hard-to-update devices.
Why This Matters Now
Critical vulnerabilities in foundational industrial automation equipment can create cascading risks across entire sectors. With threat actors increasingly targeting operational technology environments and patch cycles remaining slow, unaddressed flaws like these expose organizations to major safety, reputational, and regulatory risks.
Attack Path Analysis
Attackers exploited CVSS 10.0 vulnerabilities in Red Lion RTUs to gain initial remote access to critical industrial assets. Once inside, they executed code with the highest privileges, escalating their control. The compromise enabled lateral movement within the OT or cloud-connected industrial network, seeking other RTUs and sensitive controllers. Attackers established command and control channels, potentially through permitted or covert outbound network paths. Sensitive operational data could be exfiltrated via unmonitored or insufficiently filtered channels. Finally, the adversary may have disrupted processes, altered control logic, or rendered devices inoperable, impacting industrial operations.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited unpatched CVSS 10.0 vulnerabilities (CVE-2023-40151, CVE-2023-42770) in exposed Red Lion RTUs to achieve remote code execution.
Related CVEs
CVE-2023-42770
CVSS 10An authentication bypass vulnerability in Red Lion SixTRAK and VersaTRAK Series RTUs allows unauthenticated remote attackers to execute commands with high privileges over TCP/IP.
Affected Products:
Red Lion SixTRAK ST-IPm-8460 – Firmware 6.0.202 and later
Red Lion SixTRAK ST-IPm-6350 – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-mIPm-135-D – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-mIPm-245-D – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-IPm2m-213-D – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-IPm2m-113-D – Firmware version 4.9.114 and later
Exploit Status:
no public exploitCVE-2023-40151
CVSS 10An exposed dangerous method or function in Red Lion SixTRAK and VersaTRAK Series RTUs allows unauthenticated remote attackers to execute commands with the highest privileges when user authentication is not enabled.
Affected Products:
Red Lion SixTRAK ST-IPm-8460 – Firmware 6.0.202 and later
Red Lion SixTRAK ST-IPm-6350 – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-mIPm-135-D – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-mIPm-245-D – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-IPm2m-213-D – Firmware version 4.9.114 and later
Red Lion VersaTRAK VT-IPm2m-113-D – Firmware version 4.9.114 and later
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
User Execution
Exploitation for Privilege Escalation
Command and Scripting Interpreter
Ingress Tool Transfer
Impair Defenses
Data Encrypted for Impact
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: Section 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Asset Discovery and Vulnerability Management
Control ID: Asset Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical CVSS 10.0 vulnerabilities in Red Lion RTUs threaten energy infrastructure with full industrial control compromise, requiring immediate segmentation and threat detection capabilities.
Utilities
Remote terminal unit vulnerabilities expose utility operations to complete system takeover, demanding enhanced egress security, encrypted traffic protection, and anomaly detection systems.
Industrial Automation
SixTRAK and VersaTRAK RTU flaws enable attackers to achieve highest privilege code execution, necessitating zero trust segmentation and inline intrusion prevention systems.
Manufacturing
Industrial control system vulnerabilities threaten manufacturing operations with complete remote control compromise, requiring multicloud visibility, policy enforcement, and threat response automation.
Sources
- Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Controlhttps://thehackernews.com/2025/10/two-cvss-100-bugs-in-red-lion-rtus.htmlVerified
- Red Lion Sixnet RTUs | CISAhttps://www.cisa.gov/news-events/ics-advisories/icsa-23-320-01Verified
- CVE-2023-42770 Detail | NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-42770Verified
- CVE-2023-40151 Detail | NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-40151Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west and egress controls, and inline threat detection would have contained adversary movement, restricted remote exploitation, and prevented data exfiltration by limiting attacker reach and monitoring anomalous activity at every stage.
Control: Zero Trust Segmentation
Mitigation: Minimizes external exposure and restricts access to RTUs.
Control: Threat Detection & Anomaly Response
Mitigation: Detects anomalous escalation activity and alerts security teams.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized lateral movement between workloads.
Control: Inline IPS (Suricata)
Mitigation: Blocks or detects known C2 protocols and malicious outbound traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized outbound data transfers and egress exfiltration.
Real-time inspection and distributed policy respond to detected sabotage or disruption.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive operational data and control over industrial processes.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict direct access to industrial control systems, minimizing external exposure.
- • Enforce robust east-west traffic controls and workload identity policies to block unauthorized lateral movement between devices and segments.
- • Apply egress security and DNS/FQDN filtering to prevent data exfiltration and limit risky outbound communications from OT assets.
- • Deploy inline IPS and real-time anomaly detection to rapidly identify and respond to exploitation attempts and privilege abuse on RTUs.
- • Integrate centralized visibility and incident detection capabilities for swift response and comprehensive monitoring across cloud and OT environments.



