HIGH · 7.5

CVE-2022-2004

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service conditio...

Vulnerability Description

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
AutomationdirectD0-06Dd1 Firmware< 2.72
AutomationdirectD0-06Dd1-
AutomationdirectD0-06Dd2 Firmware< 2.72
AutomationdirectD0-06Dd2-
AutomationdirectD0-06Dr Firmware< 2.72
AutomationdirectD0-06Dr-
AutomationdirectD0-06Da Firmware< 2.72
AutomationdirectD0-06Da-
AutomationdirectD0-06Ar Firmware< 2.72
AutomationdirectD0-06Ar-
AutomationdirectD0-06Aa Firmware< 2.72
AutomationdirectD0-06Aa-
AutomationdirectD0-06Dd1-D Firmware< 2.72
AutomationdirectD0-06Dd1-D-
AutomationdirectD0-06Dd2-D Firmware< 2.72
AutomationdirectD0-06Dd2-D-
AutomationdirectD0-06Dr-D Firmware< 2.72
AutomationdirectD0-06Dr-D-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-2004?

CVE-2022-2004 is a vulnerability with a CVSS score of 7.5 (HIGH). AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service conditio...

How severe is CVE-2022-2004?

CVE-2022-2004 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-2004?

Check the references section above for vendor advisories and patch information. Affected products include: Automationdirect D0-06Dd1 Firmware, Automationdirect D0-06Dd1, Automationdirect D0-06Dd2 Firmware, Automationdirect D0-06Dd2, Automationdirect D0-06Dr Firmware.