PT-2022-10175 · Automationdirect · Automation Direct Click Plc Cpu Modules
Adeen Ayub
+2
·
Published
2022-04-04
·
Updated
2022-04-13
·
CVE-2021-32982
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Automation Direct CLICK PLC CPU Modules versions prior to v3.00
Description
The issue concerns the transmission of passwords in plaintext during unlocking and project transfers for Automation Direct CLICK PLC CPU Modules. An attacker with network visibility can observe the password exchange.
Recommendations
For versions prior to v3.00, update the firmware to version v3.00 or later to resolve the issue.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Automation Direct Click Plc Cpu Modules