QID 591300

Date Published: 2023-02-13

QID 591300: Red Lion Crimson Path Traversal Vulnerabilities(ICSA-22-321-01)

AFFECTED PRODUCTS
The following versions of Crimson 3.1 for the DA10D Protocol Converter are affected:

Crimson 3.0: Version 707.000 and prior
Crimson 3.1: Version 3126.001 and prior
Crimson 3.2: Version 3.2.0044.0 and prior

QID Detection:(Authenticated)
This QID checks for vulnerable versions of Crimson using HKLM\SOFTWARE\Classes\Crimson(version-number).Database\DefaultIcon.

Successful exploitation of this vulnerability could allow an attacker to obtain user credential hashes.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-321-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591300

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-321-01 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-321-01