CVE-2021-32978

The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-21-166-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:automationdirect:c0-10dd1e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10dd1e-d:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:automationdirect:c0-10dd2e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10dd2e-d:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:automationdirect:c0-10dre-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10dre-d:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:automationdirect:c0-10are-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10are-d:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:automationdirect:c0-11dd1e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11dd1e-d:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:automationdirect:c0-11dd2e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11dd2e-d:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:automationdirect:c0-11dre-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11dre-d:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:automationdirect:c0-11are-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11are-d:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dd1e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd1e-d:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dd2e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd2e-d:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dre-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dre-d:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:automationdirect:c0-12are-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12are-d:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dd1e-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd1e-1-d:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dd2e-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd2e-1-d:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dre-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dre-1-d:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:automationdirect:c0-12are-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12are-1-d:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dd1e-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd1e-2-d:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dd2e-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd2e-2-d:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:automationdirect:c0-12dre-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dre-2-d:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:automationdirect:c0-12are-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12are-2-d:-:*:*:*:*:*:*:*

History

13 Apr 2022, 18:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-166-02 - (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-166-02 - Third Party Advisory, US Government Resource
CWE CWE-522
CPE cpe:2.3:h:automationdirect:c0-10dd1e-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-11dd2e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-11dd1e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd1e-1-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12are-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-10dd1e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10dre-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dd2e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd1e-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-11are-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12are-2-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11are-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd2e-2-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dre-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dd1e-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dd1e-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dre-1-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dre-2-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11dd1e-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dre-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dre-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12are-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12are-1-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12are-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10dd2e-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd2e-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dd2e-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11dre-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-10are-d:-:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd2e-1-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12are-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dre-2-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-11dre-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dd2e-1-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-10dd2e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-10are-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-12dd1e-2-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-10dre-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:c0-12dd1e-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:automationdirect:c0-11dd2e-d:-:*:*:*:*:*:*:*

04 Apr 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-04 20:15

Updated : 2024-02-04 22:29


NVD link : CVE-2021-32978

Mitre link : CVE-2021-32978

CVE.ORG link : CVE-2021-32978


JSON object : View

Products Affected

automationdirect

  • c0-10dd1e-d_firmware
  • c0-12dre-1-d
  • c0-10dre-d
  • c0-11dd2e-d
  • c0-12dd2e-2-d
  • c0-10dre-d_firmware
  • c0-12are-1-d
  • c0-11dre-d
  • c0-12dd2e-2-d_firmware
  • c0-12dre-1-d_firmware
  • c0-12dd1e-2-d
  • c0-10are-d
  • c0-12dd1e-1-d_firmware
  • c0-12dd2e-d_firmware
  • c0-12dd2e-1-d
  • c0-10dd1e-d
  • c0-12dre-2-d
  • c0-12dre-d_firmware
  • c0-11dd2e-d_firmware
  • c0-11dd1e-d
  • c0-11dre-d_firmware
  • c0-12dre-2-d_firmware
  • c0-12dd1e-d_firmware
  • c0-11are-d
  • c0-10are-d_firmware
  • c0-12are-2-d
  • c0-12are-d_firmware
  • c0-12are-2-d_firmware
  • c0-12dd2e-1-d_firmware
  • c0-12are-1-d_firmware
  • c0-12dd2e-d
  • c0-11dd1e-d_firmware
  • c0-10dd2e-d_firmware
  • c0-11are-d_firmware
  • c0-12dd1e-1-d
  • c0-12dd1e-2-d_firmware
  • c0-10dd2e-d
  • c0-12dd1e-d
  • c0-12are-d
  • c0-12dre-d
CWE
CWE-522

Insufficiently Protected Credentials

CWE-256

Unprotected Storage of Credentials