CVE-2021-32978: Automation Direct CLICK PLC CPU Modules Plaintext Storage of a Password
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-32978.
What is the severity of CVE-2021-32978?
The severity of CVE-2021-32978 is high with a CVSS score of 7.5.
What is affected by CVE-2021-32978?
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 are affected by CVE-2021-32978.
How does CVE-2021-32978 work?
CVE-2021-32978 allows an attacker to read a previously entered password and lock state, potentially allowing them to unlock the affected Automation Direct CLICK PLC CPU Modules.
Is there a fix for CVE-2021-32978?
Yes, the fix for CVE-2021-32978 is to update the firmware of the affected Automation Direct CLICK PLC CPU Modules to v3.00 or later.