VYPR
Vendor

Automationdirect

Products
87
CVEs
58
Across products
208
Status
Private

Products

87
View all 87 products →

Recent CVEs

58
View all 58 CVEs →
  • CVE-2025-61934CriOct 23, 2025
    risk 0.65cvss 10.0epss 0.01

    A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files…

  • CVE-2025-36535CriMay 21, 2025
    risk 0.65cvss 10.0epss 0.01

    The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.

  • CVE-2025-0960CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.

  • CVE-2024-24963CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to…

  • CVE-2024-24962CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to…

  • CVE-2024-23601CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-21785CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.02

    A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted series of network requests can lead to unauthorized access. An attacker can send a sequence of requests to trigger this…

  • CVE-2021-32986CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed…

  • CVE-2021-32984CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC…

  • CVE-2021-32980CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is already active.

  • CVE-2020-10921CriJul 23, 2020
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue…

  • CVE-2020-10920CriJul 23, 2020
    risk 0.64cvss 9.8epss 0.05

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the control service, which…

  • CVE-2020-6969CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.02

    It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.

  • CVE-2022-2485CriAug 31, 2022
    risk 0.62cvss 9.6epss 0.00

    Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

  • CVE-2024-22187CriMay 28, 2024
    risk 0.59cvss 9.1epss 0.01

    A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to…

  • CVE-2025-55069HigSep 23, 2025
    risk 0.54cvss 8.3epss 0.00

    A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises…

  • CVE-2025-59484HigSep 23, 2025
    risk 0.54cvss 8.3epss 0.00

    The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software uses an insecure implementation of the RSA encryption algorithm.

  • CVE-2024-24959HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24958HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.01

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…

  • CVE-2024-24957HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.00

    Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to…