ZeroHour

CVE-2021-32986

CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.

Vendors
automationdirect
Products
c0-10dd1e-d firmware, c0-10dd2e-d firmware, c0-10dre-d firmware, c0-10are-d firmware, c0-11dd1e-d firmware, c0-11dd2e-d firmware, c0-11dre-d firmware, c0-11are-d firmware, c0-12dd1e-d firmware, c0-12dd2e-d firmware, c0-12dre-d firmware, c0-12are-d firmware
Weakness
CWE-288, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.