← voltar
CVE-2021-32984criticalCWE-288

Automation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or Channel

28Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 9.8epss 1.1%
probabilidade de exploração
1.1%top 38% das CVEs
exploração observada
nãonenhuma fonte reporta
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H