QID 591289

Date Published: 2023-01-13

QID 591289: Automation Direct CLICK PLC CPU Modules Unprotected Storage of Credentials Multiple Vulnerabilities (ICSA-21-166-02)

AFFECTED PRODUCTS
CLICK PLC CPU Modules: C0-1x CPUs with All firmware prior to v3.00

QID Detection Logic:
This QID checks for the Vulnerable version of Automation Direct CLICK PLC CPU Modules using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to log in as a currently or previously authenticated user or discover passwords for valid users.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-166-02 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-166-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-21-166-02