SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32986

All subsequent programming connections are allowed without authorization.

CRITICAL 9.8EPSS 1.11%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.11% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-288, CWE-863
Affected
automationdirect/c0-10dd1e-d firmware · automationdirect/c0-10dd2e-d firmware · automationdirect/c0-10dre-d firmware · automationdirect/c0-10are-d firmware · automationdirect/c0-11dd1e-d firmware · automationdirect/c0-11dd2e-d firmware · automationdirect/c0-11dre-d firmware · automationdirect/c0-11are-d firmware · automationdirect/c0-12dd1e-d firmware · automationdirect/c0-12dd2e-d firmware · automationdirect/c0-12dre-d firmware · automationdirect/c0-12are-d firmware · automationdirect/c0-12dd1e-1-d firmware · automationdirect/c0-12dd2e-1-d firmware · automationdirect/c0-12dre-1-d firmware · automationdirect/c0-12are-1-d firmware · automationdirect/c0-12dd1e-2-d firmware · automationdirect/c0-12dd2e-2-d firmware · automationdirect/c0-12dre-2-d firmware · automationdirect/c0-12are-2-d firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.