← Back

CVE-2021-32984

nvd nist
Published: Apr 4, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

Affected (20)

20 products
C0 10dd1e D Firmware
C0 10dd2e D Firmware
C0 10dre D Firmware
C0 10are D Firmware
C0 11dd1e D Firmware
C0 11dd2e D Firmware
C0 11dre D Firmware
C0 11are D Firmware
C0 12dd1e D Firmware
C0 12dd2e D Firmware
C0 12dre D Firmware
C0 12are D Firmware
C0 12dd1e 1 D Firmware
C0 12dd2e 1 D Firmware
C0 12dre 1 D Firmware
C0 12are 1 D Firmware
C0 12dd1e 2 D Firmware
C0 12dd2e 2 D Firmware
C0 12dre 2 D Firmware
C0 12are 2 D Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 10dd1e D
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 10dd2e D
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 10dre D
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 10are D
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 11dd1e D
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 11dd2e D
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 11dre D
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 11are D
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dd1e D
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dd2e D
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dre D
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12are D
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dd1e 1 D
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dd2e 1 D
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dre 1 D
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12are 1 D
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dd1e 2 D
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dd2e 2 D
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12dre 2 D
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.00
Running on/withPlatform Versions
Automationdirect
C0 12are 2 D
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.