« Back to list

Automationdirect

Automationdirect C0-12dd1e-2-d Firmware: vulnerabilities and CVEs

Automationdirect C0-12dd1e-2-d Firmware has 5 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months0
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-32986Critical (9.8)1.1%—Apr 4, 2022
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains…
CVE-2021-32984Critical (9.8)1.1%—Apr 4, 2022
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked…
CVE-2021-32982High (7.5)0.65%—Apr 4, 2022
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password…
CVE-2021-32980Critical (9.8)1.1%—Apr 4, 2022
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is…
CVE-2021-32978High (7.5)1.0%—Apr 4, 2022
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation…

Other products by Automationdirect