CVE-2022-2485: AutomationDirect Stride Field I/O Cleartext Transmission of Sensitive Information

Published Aug 31, 2022
·
Updated

Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

Affected Software

34 affected components
AutomationDirect SIO-MB04RTDS, firmware version prior to v8.3.4.0
AutomationDirect SIO- MB04ADS, firmware version prior to v8.4.3.0
AutomationDirect SIO-MB04THMS, firmware version prior to v8.5.4.0
AutomationDirect SIO-MB08ADS-1, firmware version prior to v8.6.3.0
AutomationDirect SIO-MB08ADS-2, firmware version prior to v8.7.3.0
AutomationDirect SIO-MB08THMS, firmware version prior to v8.8.4.0
AutomationDirect SIO-MB04DAS, firmware version prior to v8.11.3.0
AutomationDirect SIO-MB12CDR, firmware version prior to v8.0.4.0
AutomationDirect SIO-MB16CDD2, firmware version prior to v8.1.4.0
AutomationDirect SIO-MB16ND3, firmware version prior to v8.2.4.00
AutomationDirect SIO-MB12CDR, batch number (B/N) 5714442222
AutomationDirect SIO-MB04ADS, B/N 5714442222
AutomationDirect SIO-MB04THMS, B/N 57141862221
AutomationDirect SIO-MB04DAS, B/N 4714432222
AutomationDirect Sio-mb04rtds Firmware<8.3.4.0
AutomationDirect Sio-mb04rtds
AutomationDirect Sio-mb04ads Firmware<8.4.3.0
AutomationDirect Sio-mb04ads
AutomationDirect Sio-mb04thms Firmware<8.5.4.0
AutomationDirect Sio-mb04thms
AutomationDirect Sio-mb08ads-1 Firmware<8.6.3.0
AutomationDirect Sio-mb08ads-1
AutomationDirect Sio-mb08ads-2 Firmware<8.7.3.0
AutomationDirect Sio-mb08ads-2
AutomationDirect Sio-mb08thms Firmware<8.8.4.0
AutomationDirect Sio-mb08thms
AutomationDirect Sio-mb04das Firmware<8.11.3.0
AutomationDirect Sio-mb04das
AutomationDirect Sio-mb12cdr Firmware<8.0.4.0
AutomationDirect Sio-mb12cdr
AutomationDirect Sio-mb16cdd2 Firmware<8.1.4.0
AutomationDirect Sio-mb16cdd2
AutomationDirect Sio-mb16nd3 Firmware<8.2.4.0
AutomationDirect Sio-mb16nd3

Remediation

Information

AutomationDirect recommends users upgrade the Stride Modbus Field I/O units listed in the affected products section with the firmware associated with the part number. Firmware can be downloaded from the AutomationDirect software downloads page. The modules with a listed B/N number in the affected products section have a firmware update issue and must be returned to AutomationDirect for replacement modules; users can create an RMA on the AutomationDirect website. Automation networks and systems may have built-in password protection schemes, but this is only one step in securing systems. Automation control system networks must incorporate data protection and security measures at least as robust as a typical business computer system. AutomationDirect recommends users of PLCs, HMI products and SCADA systems perform their own network security analysis to determine the proper level of security required for their application. See AutomationDirect product advisory number PA-COM-006 for more information.

Event History

Aug 31, 2022
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
RemedyDescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via ICS·12:47 AM
SeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2022-2485?

CVE-2022-2485 is a vulnerability that allows any attempt to log into AutomationDirect Stride Field I/O with a web browser to result in the device responding with its password in the communication packets.

2

What is the severity of CVE-2022-2485?

The severity of CVE-2022-2485 is critical with a severity value of 7.5.

3

Which software versions are affected by CVE-2022-2485?

Versions up to exclusive 8.3.4.0 of AutomationDirect Sio-mb04rtds Firmware, up to exclusive 8.4.3.0 of AutomationDirect Sio-mb04ads Firmware, up to exclusive 8.5.4.0 of AutomationDirect Sio-mb04thms Firmware, up to exclusive 8.6.3.0 of AutomationDirect Sio-mb08ads-1 Firmware, up to exclusive 8.7.3.0 of AutomationDirect Sio-mb08ads-2 Firmware, up to exclusive 8.8.4.0 of AutomationDirect Sio-mb08thms Firmware, up to exclusive 8.11.3.0 of AutomationDirect Sio-mb04das Firmware, up to exclusive 8.0.4.0 of AutomationDirect Sio-mb12cdr Firmware, up to exclusive 8.1.4.0 of AutomationDirect Sio-mb16cdd2 Firmware, up to exclusive 8.2.4.0 of AutomationDirect Sio-mb16nd3 Firmware.

4

How can I fix CVE-2022-2485?

To fix CVE-2022-2485, users should update their AutomationDirect Stride Field I/O devices to a version that is not vulnerable.

5

Where can I find more information about CVE-2022-2485?

You can find more information about CVE-2022-2485 in the product advisory document provided by AutomationDirect and the advisory published by CISA.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203