Insecure Password Exchange in Automation Direct CLICK PLC CPU Modules

Insecure Password Exchange in Automation Direct CLICK PLC CPU Modules

CVE-2021-32982 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.

Learn more about our Network Penetration Testing.