CVE-2022-2485: AutomationDirect Stride Field I/O Cleartext Transmission of Sensitive Information
Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-2485?
CVE-2022-2485 is a vulnerability that allows any attempt to log into AutomationDirect Stride Field I/O with a web browser to result in the device responding with its password in the communication packets.
What is the severity of CVE-2022-2485?
The severity of CVE-2022-2485 is critical with a severity value of 7.5.
Which software versions are affected by CVE-2022-2485?
Versions up to exclusive 8.3.4.0 of AutomationDirect Sio-mb04rtds Firmware, up to exclusive 8.4.3.0 of AutomationDirect Sio-mb04ads Firmware, up to exclusive 8.5.4.0 of AutomationDirect Sio-mb04thms Firmware, up to exclusive 8.6.3.0 of AutomationDirect Sio-mb08ads-1 Firmware, up to exclusive 8.7.3.0 of AutomationDirect Sio-mb08ads-2 Firmware, up to exclusive 8.8.4.0 of AutomationDirect Sio-mb08thms Firmware, up to exclusive 8.11.3.0 of AutomationDirect Sio-mb04das Firmware, up to exclusive 8.0.4.0 of AutomationDirect Sio-mb12cdr Firmware, up to exclusive 8.1.4.0 of AutomationDirect Sio-mb16cdd2 Firmware, up to exclusive 8.2.4.0 of AutomationDirect Sio-mb16nd3 Firmware.
How can I fix CVE-2022-2485?
To fix CVE-2022-2485, users should update their AutomationDirect Stride Field I/O devices to a version that is not vulnerable.
Where can I find more information about CVE-2022-2485?
You can find more information about CVE-2022-2485 in the product advisory document provided by AutomationDirect and the advisory published by CISA.