CRITICAL · 9.8

CVE-2021-32984

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to...

Vulnerability Description

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AutomationdirectC0-10Dd1E-D Firmware< 3.00
AutomationdirectC0-10Dd1E-D-
AutomationdirectC0-10Dd2E-D Firmware< 3.00
AutomationdirectC0-10Dd2E-D-
AutomationdirectC0-10Dre-D Firmware< 3.00
AutomationdirectC0-10Dre-D-
AutomationdirectC0-10Are-D Firmware< 3.00
AutomationdirectC0-10Are-D-
AutomationdirectC0-11Dd1E-D Firmware< 3.00
AutomationdirectC0-11Dd1E-D-
AutomationdirectC0-11Dd2E-D Firmware< 3.00
AutomationdirectC0-11Dd2E-D-
AutomationdirectC0-11Dre-D Firmware< 3.00
AutomationdirectC0-11Dre-D-
AutomationdirectC0-11Are-D Firmware< 3.00
AutomationdirectC0-11Are-D-
AutomationdirectC0-12Dd1E-D Firmware< 3.00
AutomationdirectC0-12Dd1E-D-
AutomationdirectC0-12Dd2E-D Firmware< 3.00
AutomationdirectC0-12Dd2E-D-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-32984?

CVE-2021-32984 is a vulnerability with a CVSS score of 9.8 (CRITICAL). All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to...

How severe is CVE-2021-32984?

CVE-2021-32984 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-32984?

Check the references section above for vendor advisories and patch information. Affected products include: Automationdirect C0-10Dd1E-D Firmware, Automationdirect C0-10Dd1E-D, Automationdirect C0-10Dd2E-D Firmware, Automationdirect C0-10Dd2E-D, Automationdirect C0-10Dre-D Firmware.