AutomationDirect CLICK PLUS是美国AutomationDirect公司的一款小型可编程逻辑控制器。 AutomationDirect CLICK PLUS 3.60版本存在安全漏洞,该漏洞源于KOPR协议授权不当,可能导致低权限用户越权读取和修改PLC变量。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AutomationDirect | CLICK PLUS C0-0x CPU firmware | 0 ~ v3.71 | - |
|
| AutomationDirect | CLICK PLUS C0-1x CPU firmware | 0 ~ v3.71 | - |
|
| AutomationDirect | CLICK PLUS C2-x CPU firmware | 0 ~ v3.71 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-55069 | 8.3 HIGH | AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator |
| CVE-2025-59484 | 8.3 HIGH | AutomationDirect CLICK PLUS Use of a Broken or Risky Cryptographic Algorithm |
| CVE-2025-58473 | 5.9 MEDIUM | AutomationDirect CLICK PLUS Improper Resource Shutdown or Release |
| CVE-2025-57882 | 5.9 MEDIUM | AutomationDirect CLICK PLUS Improper Resource Shutdown or Release |
| CVE-2025-58069 | 5.3 MEDIUM | AutomationDirect CLICK PLUS Use of Hard-coded Cryptographic Key |
| CVE-2025-54855 | 4.2 MEDIUM | AutomationDirect CLICK PLUS Cleartext Storage of Sensitive Information |
No comments yet