← back
CVE-2021-32980criticalCWE-288

Automation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or Channel

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is already active.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H