The Containment Era is here. →Explore

Executive Summary

In October 2025, two critical vulnerabilities (CVE-2023-40151 and CVE-2023-42770) were publicly disclosed in Red Lion Sixnet RTU devices, which are widely used for industrial automation and critical infrastructure. Both flaws received a CVSS 10.0 rating, underscoring their exploitability and impact. Attackers exploiting these vulnerabilities could achieve remote code execution with the highest privileges, granting them full control over affected devices. These RTUs are often deployed in energy, utilities, and manufacturing, raising concerns about the potential for business disruption, safety risks, and further attacks via compromised operational technology networks.

This incident is particularly relevant as it highlights how legacy and specialized industrial control systems remain a prime target for threat actors leveraging zero-day vulnerabilities. The convergence of IT and OT, combined with growing regulatory scrutiny and an uptick in supply chain exposures, means that organizations must refocus on asset visibility and patch management for embedded and hard-to-update devices.

Why This Matters Now

Critical vulnerabilities in foundational industrial automation equipment can create cascading risks across entire sectors. With threat actors increasingly targeting operational technology environments and patch cycles remaining slow, unaddressed flaws like these expose organizations to major safety, reputational, and regulatory risks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerabilities showcased critical gaps in patch management, network segmentation, and encrypted traffic enforcement within industrial control environments, highlighting insufficient alignment with security controls like NIST 800-53 and PCI DSS.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west and egress controls, and inline threat detection would have contained adversary movement, restricted remote exploitation, and prevented data exfiltration by limiting attacker reach and monitoring anomalous activity at every stage.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Minimizes external exposure and restricts access to RTUs.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Detects anomalous escalation activity and alerts security teams.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevents unauthorized lateral movement between workloads.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Blocks or detects known C2 protocols and malicious outbound traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocks unauthorized outbound data transfers and egress exfiltration.

Impact (Mitigations)

Real-time inspection and distributed policy respond to detected sabotage or disruption.

Impact at a Glance

Affected Business Functions

  • Industrial Control Systems Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive operational data and control over industrial processes.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict direct access to industrial control systems, minimizing external exposure.
  • Enforce robust east-west traffic controls and workload identity policies to block unauthorized lateral movement between devices and segments.
  • Apply egress security and DNS/FQDN filtering to prevent data exfiltration and limit risky outbound communications from OT assets.
  • Deploy inline IPS and real-time anomaly detection to rapidly identify and respond to exploitation attempts and privilege abuse on RTUs.
  • Integrate centralized visibility and incident detection capabilities for swift response and comprehensive monitoring across cloud and OT environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image