You are here

Red Lion Controls Crimson (ICSA-19-248-01)

Red Lion Controls Crimson (ICSA-19-248-01)

Created: Tuesday, September 10, 2019 - 09:24

The NCCIC has published an advisory on use after free, improper restriction of operations within the bounds of a memory buffer, pointer issues, and use of hard-coded cryptographic key vulnerabilities in Red Lion Controls Crimson. Versions 3.0 and prior and versions 3.1 and prior, to release 3112.00, are affected. Red Lion Controls recommends users migrate to Crimson 3.1 release 3112.00 or later where the model choice allows. The NCCIC also recommends a series of measures to mitigate the vulnerabilities. Read the advisory at CISA.