CVE-2020-6969: Critical severity AutomationDirect C-more Ea9-rhi Firmware vulnerability
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
C-More Touch Panels EA9to a version that resolves this vulnerability.Fixed in 6.53 - Compensating control
Apply file protection to prevent unmasking credentials and sensitive information on “unprotected” project files, so attackers cannot remotely access C-More Touch Panels EA9 series and manipulate system configurations.
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-6969.
What is the severity level of CVE-2020-6969?
The severity level of CVE-2020-6969 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2020-6969?
The C-More Touch Panels EA9 series firmware versions prior to 6.53 are affected by CVE-2020-6969.
What is the impact of CVE-2020-6969?
CVE-2020-6969 allows an attacker to remotely access the C-More Touch Panels EA9 series and manipulate system configurations by unmasking credentials and other sensitive information on unprotected project files.
Where can I find more information about CVE-2020-6969?
You can find more information about CVE-2020-6969 on the US-CERT website at https://www.us-cert.gov/ics/advisories/icsa-20-035-01.