CVE-2021-32982

EUVD-2021-19703
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
automationdirectc0-10dd1e-d_firmware
𝑥
< 3.00
automationdirectc0-10dd2e-d_firmware
𝑥
< 3.00
automationdirectc0-10dre-d_firmware
𝑥
< 3.00
automationdirectc0-10are-d_firmware
𝑥
< 3.00
automationdirectc0-11dd1e-d_firmware
𝑥
< 3.00
automationdirectc0-11dd2e-d_firmware
𝑥
< 3.00
automationdirectc0-11dre-d_firmware
𝑥
< 3.00
automationdirectc0-11are-d_firmware
𝑥
< 3.00
automationdirectc0-12dd1e-d_firmware
𝑥
< 3.00
automationdirectc0-12dd2e-d_firmware
𝑥
< 3.00
automationdirectc0-12dre-d_firmware
𝑥
< 3.00
automationdirectc0-12are-d_firmware
𝑥
< 3.00
automationdirectc0-12dd1e-1-d_firmware
𝑥
< 3.00
automationdirectc0-12dd2e-1-d_firmware
𝑥
< 3.00
automationdirectc0-12dre-1-d_firmware
𝑥
< 3.00
automationdirectc0-12are-1-d_firmware
𝑥
< 3.00
automationdirectc0-12dd1e-2-d_firmware
𝑥
< 3.00
automationdirectc0-12dd2e-2-d_firmware
𝑥
< 3.00
automationdirectc0-12dre-2-d_firmware
𝑥
< 3.00
automationdirectc0-12are-2-d_firmware
𝑥
< 3.00
𝑥
= Vulnerable software versions