CVE-2025-67652: AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password
An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type of exploitation, leaving sensitive information more vulnerable.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67652?
CVE-2025-67652 has been classified as a high-severity vulnerability due to the potential unauthorized access it can allow.
How do I fix CVE-2025-67652?
To mitigate CVE-2025-67652, implement strong encryption for stored passwords and limit access to project files.
What systems are affected by CVE-2025-67652?
CVE-2025-67652 affects the AutomationDirect CLICK Programmable Logic Controller.
What risks does CVE-2025-67652 pose?
CVE-2025-67652 could allow attackers to impersonate users, escalate privileges, or gain unauthorized access to systems.
Is there a workaround for CVE-2025-67652?
Currently, restricting access to project files and enhancing password security can serve as a temporary workaround for CVE-2025-67652.