CVE-2021-32982: Automation Direct CLICK PLC CPU Modules Cleartext Transmission of Sensitive Information
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID for this issue is CVE-2021-32982.
What is the severity of CVE-2021-32982?
The severity of CVE-2021-32982 is high with a CVSS score of 7.5.
What is the affected software for CVE-2021-32982?
The affected software for CVE-2021-32982 are Automation Direct CLICK PLC CPU Modules with C0-1x CPUs and firmware versions prior to v3.00.
What is the impact of CVE-2021-32982?
CVE-2021-32982 allows an attacker with network visibility to observe the password exchange, putting the system at risk of unauthorized access.
Is there a fix available for CVE-2021-32982?
Yes, updating the firmware of the affected Automation Direct CLICK PLC CPU Modules to v3.00 or later will fix the vulnerability.