CVE-2022-2485
31.08.2022, 16:15
Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.Enginsight
Vendor | Product | Version |
---|---|---|
automationdirect | sio-mb04rtds_firmware | 𝑥 < 8.3.4.0 |
automationdirect | sio-mb04ads_firmware | 𝑥 < 8.4.3.0 |
automationdirect | sio-mb04thms_firmware | 𝑥 < 8.5.4.0 |
automationdirect | sio-mb08ads-1_firmware | 𝑥 < 8.6.3.0 |
automationdirect | sio-mb08ads-2_firmware | 𝑥 < 8.7.3.0 |
automationdirect | sio-mb08thms_firmware | 𝑥 < 8.8.4.0 |
automationdirect | sio-mb04das_firmware | 𝑥 < 8.11.3.0 |
automationdirect | sio-mb12cdr_firmware | 𝑥 < 8.0.4.0 |
automationdirect | sio-mb16cdd2_firmware | 𝑥 < 8.1.4.0 |
automationdirect | sio-mb16nd3_firmware | 𝑥 < 8.2.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration