CVE-2021-32982

Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
automationdirectc0-10dd1e-d_firmware
𝑥
< 3.00
automationdirectc0-10dd2e-d_firmware
𝑥
< 3.00
automationdirectc0-10dre-d_firmware
𝑥
< 3.00
automationdirectc0-10are-d_firmware
𝑥
< 3.00
automationdirectc0-11dd1e-d_firmware
𝑥
< 3.00
automationdirectc0-11dd2e-d_firmware
𝑥
< 3.00
automationdirectc0-11dre-d_firmware
𝑥
< 3.00
automationdirectc0-11are-d_firmware
𝑥
< 3.00
automationdirectc0-12dd1e-d_firmware
𝑥
< 3.00
automationdirectc0-12dd2e-d_firmware
𝑥
< 3.00
automationdirectc0-12dre-d_firmware
𝑥
< 3.00
automationdirectc0-12are-d_firmware
𝑥
< 3.00
automationdirectc0-12dd1e-1-d_firmware
𝑥
< 3.00
automationdirectc0-12dd2e-1-d_firmware
𝑥
< 3.00
automationdirectc0-12dre-1-d_firmware
𝑥
< 3.00
automationdirectc0-12are-1-d_firmware
𝑥
< 3.00
automationdirectc0-12dd1e-2-d_firmware
𝑥
< 3.00
automationdirectc0-12dd2e-2-d_firmware
𝑥
< 3.00
automationdirectc0-12dre-2-d_firmware
𝑥
< 3.00
automationdirectc0-12are-2-d_firmware
𝑥
< 3.00
𝑥
= Vulnerable software versions