CVE-2025-54855: AutomationDirect CLICK PLUS Cleartext Storage of Sensitive Information
Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal credentials stored in clear text.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54855?
The severity of CVE-2025-54855 is high due to the risk of sensitive information exposure.
How do I fix CVE-2025-54855?
To fix CVE-2025-54855, upgrade to version 3.71 or higher of the affected CLICK PLUS software or firmware.
Who is affected by CVE-2025-54855?
CVE-2025-54855 affects users of AutomationDirect CLICK PLUS software and specific CPU firmware versions.
What type of vulnerability is CVE-2025-54855?
CVE-2025-54855 is a vulnerability involving cleartext storage of sensitive information that can lead to credential theft.
Can CVE-2025-54855 be exploited remotely?
No, CVE-2025-54855 requires local access to the file system to exploit the vulnerability.