AutomationDirect CLICK PLUS是美国AutomationDirect公司的一款小型可编程逻辑控制器。 AutomationDirect CLICK PLUS 3.60版本存在安全漏洞,该漏洞源于固件中使用硬编码AES密钥保护KOPS会话初始消息,可能导致密钥泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AutomationDirect | CLICK PLUS C0-0x CPU firmware | 0 ~ v3.71 | - |
|
| AutomationDirect | CLICK PLUS C0-1x CPU firmware | 0 ~ v3.71 | - |
|
| AutomationDirect | CLICK PLUS C2-x CPU firmware | 0 ~ v3.71 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-55069 | 8.3 HIGH | AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator |
| CVE-2025-59484 | 8.3 HIGH | AutomationDirect CLICK PLUS Use of a Broken or Risky Cryptographic Algorithm |
| CVE-2025-55038 | 6.8 MEDIUM | AutomationDirect CLICK PLUS Missing Authorization |
| CVE-2025-58473 | 5.9 MEDIUM | AutomationDirect CLICK PLUS Improper Resource Shutdown or Release |
| CVE-2025-57882 | 5.9 MEDIUM | AutomationDirect CLICK PLUS Improper Resource Shutdown or Release |
| CVE-2025-54855 | 4.2 MEDIUM | AutomationDirect CLICK PLUS Cleartext Storage of Sensitive Information |
No comments yet