Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15088
http://www.securityfocus.com/bid/9618
http://www.securityfocus.com/archive/1/353211
http://www.securiteam.com/securitynews/5SP0C0KC0A.html