CVE-2021-32984: Automation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or Channel
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-32984?
CVE-2021-32984 is a vulnerability that allows all programming connections to receive the same unlocked privileges, leading to privilege escalation.
How does CVE-2021-32984 affect Automation Direct CLICK PLC CPU Modules?
CVE-2021-32984 affects Automation Direct CLICK PLC CPU Modules with firmware prior to v3.00.
What is the severity of CVE-2021-32984?
CVE-2021-32984 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2021-32984?
An attacker can exploit CVE-2021-32984 by connecting to the unlocked Automation Direct CLICK PLC CPU Modules and reading the project file.
Is Automationdirect C0-10dd1e-d vulnerable to CVE-2021-32984?
No, Automationdirect C0-10dd1e-d is not vulnerable to CVE-2021-32984.