CVE-2022-2004

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
automationdirectd0-06dd1_firmware
𝑥
< 2.72
automationdirectd0-06dd2_firmware
𝑥
< 2.72
automationdirectd0-06dr_firmware
𝑥
< 2.72
automationdirectd0-06da_firmware
𝑥
< 2.72
automationdirectd0-06ar_firmware
𝑥
< 2.72
automationdirectd0-06aa_firmware
𝑥
< 2.72
automationdirectd0-06dd1-d_firmware
𝑥
< 2.72
automationdirectd0-06dd2-d_firmware
𝑥
< 2.72
automationdirectd0-06dr-d_firmware
𝑥
< 2.72
𝑥
= Vulnerable software versions