CVE-2022-2006: AutomationDirect C-more EA9 HMI Uncontrolled Search Path Element
AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code during the installation process. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-2006.
What is the severity rating of CVE-2022-2006?
The severity rating of CVE-2022-2006 is 7.8 (high).
Which software versions are affected by CVE-2022-2006?
AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73, EA9-T6CL-R versions prior to 6.73, and EA9-T7CL versions prior to 6.7 are affected by CVE-2022-2006.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by executing code during the installation process of AutomationDirect DirectLOGIC, potentially allowing them to gain unauthorized access.
Is there a fix available for CVE-2022-2006?
Yes, upgrading to version 6.73 or higher of AutomationDirect C-more EA9 EA9-T6CL, EA9-T6CL-R, and EA9-T7CL will address this vulnerability.