Vulnerability Description
AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Automationdirect | D0-06Dd1 Firmware | < 2.72 |
| Automationdirect | D0-06Dd1 | - |
| Automationdirect | D0-06Dd2 Firmware | < 2.72 |
| Automationdirect | D0-06Dd2 | - |
| Automationdirect | D0-06Dr Firmware | < 2.72 |
| Automationdirect | D0-06Dr | - |
| Automationdirect | D0-06Da Firmware | < 2.72 |
| Automationdirect | D0-06Da | - |
| Automationdirect | D0-06Ar Firmware | < 2.72 |
| Automationdirect | D0-06Ar | - |
| Automationdirect | D0-06Aa Firmware | < 2.72 |
| Automationdirect | D0-06Aa | - |
| Automationdirect | D0-06Dd1-D Firmware | < 2.72 |
| Automationdirect | D0-06Dd1-D | - |
| Automationdirect | D0-06Dd2-D Firmware | < 2.72 |
| Automationdirect | D0-06Dd2-D | - |
| Automationdirect | D0-06Dr-D Firmware | < 2.72 |
| Automationdirect | D0-06Dr-D | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-03PatchThird Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-03PatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-2004?
CVE-2022-2004 is a vulnerability with a CVSS score of 7.5 (HIGH). AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service conditio...
How severe is CVE-2022-2004?
CVE-2022-2004 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2004?
Check the references section above for vendor advisories and patch information. Affected products include: Automationdirect D0-06Dd1 Firmware, Automationdirect D0-06Dd1, Automationdirect D0-06Dd2 Firmware, Automationdirect D0-06Dd2, Automationdirect D0-06Dr Firmware.