Vulnerability Description
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Automationdirect | C0-10Dd1E-D Firmware | < 3.00 |
| Automationdirect | C0-10Dd1E-D | - |
| Automationdirect | C0-10Dd2E-D Firmware | < 3.00 |
| Automationdirect | C0-10Dd2E-D | - |
| Automationdirect | C0-10Dre-D Firmware | < 3.00 |
| Automationdirect | C0-10Dre-D | - |
| Automationdirect | C0-10Are-D Firmware | < 3.00 |
| Automationdirect | C0-10Are-D | - |
| Automationdirect | C0-11Dd1E-D Firmware | < 3.00 |
| Automationdirect | C0-11Dd1E-D | - |
| Automationdirect | C0-11Dd2E-D Firmware | < 3.00 |
| Automationdirect | C0-11Dd2E-D | - |
| Automationdirect | C0-11Dre-D Firmware | < 3.00 |
| Automationdirect | C0-11Dre-D | - |
| Automationdirect | C0-11Are-D Firmware | < 3.00 |
| Automationdirect | C0-11Are-D | - |
| Automationdirect | C0-12Dd1E-D Firmware | < 3.00 |
| Automationdirect | C0-12Dd1E-D | - |
| Automationdirect | C0-12Dd2E-D Firmware | < 3.00 |
| Automationdirect | C0-12Dd2E-D | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-166-02Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-166-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-32984?
CVE-2021-32984 is a vulnerability with a CVSS score of 9.8 (CRITICAL). All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to...
How severe is CVE-2021-32984?
CVE-2021-32984 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-32984?
Check the references section above for vendor advisories and patch information. Affected products include: Automationdirect C0-10Dd1E-D Firmware, Automationdirect C0-10Dd1E-D, Automationdirect C0-10Dd2E-D Firmware, Automationdirect C0-10Dd2E-D, Automationdirect C0-10Dre-D Firmware.