Two critical vulnerabilities have been discovered in Red Lion Sixnet remote terminal units (RTUs), which are widely deployed in industrial control systems across sectors such as energy, water and wastewater treatment, transportation, utilities, and manufacturing. The vulnerabilities, identified as CVE-2023-42770 and CVE-2023-40151, both carry the maximum CVSS score of 10.0, indicating their severity and potential for exploitation. CVE-2023-42770 is an authentication bypass flaw that arises because the affected RTUs only enforce authentication on UDP port 1594, while the same port over TCP does not require authentication, allowing attackers to send unauthorized commands. CVE-2023-40151 is a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary Linux shell commands as root via the Sixnet Universal protocol. These vulnerabilities can be chained, enabling a remote attacker to bypass all authentication and gain full control over the RTU, potentially leading to significant disruptions in critical infrastructure operations. The flaws were discovered by Claroty’s Team82, who withheld full exploit details to give organizations time to patch their systems. Red Lion’s Sixnet IO Tool Kit, a Windows-based utility, is used to configure these RTUs and communicates using a proprietary protocol that was found to be susceptible to these attacks. The vulnerabilities affect both the SixTRAK and VersaTRAK series of RTUs. The user-permission system implemented in the protocol was intended to restrict access, but the lack of authentication checks on TCP traffic undermines this security measure. Security experts have warned that exploitation of these vulnerabilities could allow attackers to manipulate, disrupt, or destroy industrial processes controlled by the compromised RTUs. The affected devices are integral to automation, control, and data acquisition in industrial environments, making the risk of exploitation particularly concerning. Organizations using these RTUs are urged to apply available patches and review network segmentation to limit exposure. The vulnerabilities highlight the ongoing risks associated with legacy industrial protocols and the importance of rigorous security testing in critical infrastructure environments. Claroty’s report provides technical details on the flaws and emphasizes the need for immediate remediation. The disclosure underscores the potential for unauthenticated remote attacks to have far-reaching impacts on essential services. Security professionals recommend monitoring for unusual network activity on port 1594 and implementing strict access controls. The incident serves as a reminder of the critical need for robust authentication and secure protocol design in industrial control systems.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A new report detailed two maximum-severity flaws affecting Red Lion remote terminal units (RTUs), warning that successful exploitation could give attackers full control over industrial devices. The disclosures established the core security issue described across the references.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.