CVE-2022-2005: AutomationDirect C-more EA9 HMI Cleartext Transmission

Published Aug 31, 2022
·
Updated

AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;

Affected Software

37 affected components
AutomationDirect C-more EA9 with the following part numbers, all versions prior to 6.73:  EA9-T6CL EA9-T6CL-R EA9-T7CL EA9-T7CL-R EA9-T8CL EA9-T10CL EA9-T10WCL EA9-T12CL EA9-T15CL EA9-T15CL-R EA9-RHMI EA9-PGMSW
AutomationDirect EA9-T6CL
AutomationDirect EA9-T6CL-R
AutomationDirect EA9-T7CL
AutomationDirect EA9-T7CL-R
AutomationDirect EA9-T8CL
AutomationDirect EA9-T10CL
AutomationDirect EA9-T10WCL
AutomationDirect EA9-T12CL
AutomationDirect EA9-T15CL
AutomationDirect EA9-T15CL-R
AutomationDirect EA9-RHMI
AutomationDirect EA9-PGMSW
AutomationDirect C-more Ea9-t6cl Firmware<6.73
AutomationDirect C-more Ea9-t6cl
AutomationDirect C-more Ea9-t6cl-r Firmware<6.73
AutomationDirect C-more Ea9-t6cl-r
AutomationDirect C-more Ea9-t7cl Firmware<6.73
AutomationDirect C-more Ea9-t7cl
AutomationDirect C-more Ea9-t7cl-r Firmware<6.73
AutomationDirect C-more Ea9-t7cl-r
AutomationDirect C-more Ea9-t8cl Firmware<6.73
AutomationDirect C-more Ea9-t8cl
AutomationDirect C-more Ea9-t10cl Firmware<6.73
AutomationDirect C-more Ea9-t10cl
AutomationDirect C-more Ea9-t10wcl Firmware<6.73
AutomationDirect C-more Ea9-t10wcl
AutomationDirect C-more Ea9-t12cl Firmware<6.73
AutomationDirect C-more Ea9-t12cl
AutomationDirect C-more Ea9-t15cl Firmware<6.73
AutomationDirect C-more Ea9-t15cl
AutomationDirect C-more Ea9-t15cl-r Firmware<6.73
AutomationDirect C-more Ea9-t15cl-r
AutomationDirect C-more Ea9-rhmi Firmware<6.73
AutomationDirect C-more Ea9-rhmi
AutomationDirect C-more Ea9-pgmsw Firmware<6.73
AutomationDirect C-more Ea9-pgmsw

Remediation

Information

AutomationDirect recommends users upgrade to firmware Version 6.73 or later, which supports TLS security options for the webserver. While automation networks and systems have built-in password protection schemes, this is only one step in securing the affected systems. Automation control system networks must incorporate data protection and security measures at least as robust as a typical business computer system. AutomationDirect recommends users of PLCs, HMI products, and other SCADA system products perform independent network security analysis to determine the proper level of security required for the application. AutomationDirect has identified the following mitigations for instances where systems cannot be upgraded to Version 6.73 or later: The Webserver feature can be disabled on the HMI using the programming software. Place the HMI panel behind a VPN: Access to and from critical control system assets in the modern environment is usually LAN based, but still should be considered remote if the operator is traversing across different networks. virtual private networking (VPN) is often considered the best approach in securing trans-network communication.

Event History

Aug 31, 2022
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
RemedyDescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-2005?

CVE-2022-2005 is a vulnerability in the AutomationDirect C-more EA9 HTTP webserver that allows an attacker to obtain login credentials and login as a valid user.

2

How does CVE-2022-2005 affect AutomationDirect C-more EA9?

CVE-2022-2005 affects AutomationDirect C-more EA9 versions prior to 6.73, allowing an attacker to obtain login credentials and login as a valid user.

3

What is the severity of CVE-2022-2005?

CVE-2022-2005 has a severity rating of 7.5 (high).

4

How can an attacker exploit CVE-2022-2005?

An attacker can exploit CVE-2022-2005 by intercepting and obtaining the insecurely transmitted credentials between the client and web server.

5

Is there a fix for CVE-2022-2005?

Yes, upgrading to AutomationDirect C-more EA9 version 6.73 or newer will fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203