VYPR
Unrated severityNVD Advisory· Published Apr 4, 2022· Updated Apr 16, 2025

Automation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or Channel

CVE-2021-32984

Description

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.