← volver
CVE-2021-32986criticalCWE-288

Automation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or Channel

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.8epss 1.1%
probabilidad de explotación
1.1%top 38% de las CVE
explotación observada
noninguna fuente lo reporta
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H