CVE-2020-27285: Redlion Crimson

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

Affected products

Published 2021-01-06. Last modified 2026-06-17.