CVE-2024-25138: AutomationDirect C-MORE EA9 HMI Plaintext Storage of a Password
Published Mar 26, 2024
·Updated
In AutomationDirect C-MORE EA9 HMI,
credentials used by the platform are stored as plain text on the device.
Affected Software
1 affected component
AutomationDirect C-MORE EA9 HMI
Remediation
Information
AutomationDirect recommends that users update C-MORE EA9 HMI to V6.78 https://www.automationdirect.com/support/software-downloads .
Event History
Mar 26, 2024
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25138?
CVE-2024-25138 is considered a high severity vulnerability due to the exposure of plain text credentials.
2
How do I fix CVE-2024-25138?
To mitigate CVE-2024-25138, ensure that sensitive credentials are encrypted and not stored in plain text on the device.
3
What systems are affected by CVE-2024-25138?
CVE-2024-25138 affects the AutomationDirect C-MORE EA9 HMI system.
4
What risks are associated with CVE-2024-25138?
The risks associated with CVE-2024-25138 include unauthorized access to the HMI system and potential exploitation by attackers.
5
Is there a workaround for CVE-2024-25138?
Currently, there are no official workarounds for CVE-2024-25138 other than following security best practices regarding credential management.