CVE-2025-55069: AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55069?
The severity of CVE-2025-55069 is considered high due to its impact on the security of the random number generation process.
How do I fix CVE-2025-55069?
To fix CVE-2025-55069, upgrade the affected firmware versions of the CLICK PLUS PLC to version 3.71 or later.
Which products are affected by CVE-2025-55069?
CVE-2025-55069 affects CLICK PLUS C0-0x, C0-1x, and C2-x CPU firmware versions up to 3.71.
What are the potential risks associated with CVE-2025-55069?
The potential risks include exploitation of predictable random number generation that could lead to unauthorized access or control of the PLC.
Is there a patch available for CVE-2025-55069?
Yes, a patch is available in firmware version 3.71 that addresses the vulnerability in CVE-2025-55069.