Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NMEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
Any version before v3.71
affected
Default status
unaffected
Any version before v3.71
affected
Default status
unaffected
Any version before v3.71
affected
Description
The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session.
Problem types
CWE-321 Use of Hard-coded Cryptographic Key
Product status
Any version before v3.71
Any version before v3.71
Any version before v3.71
Credits
Luca Borzacchiello and Diego Zaffaroni of Nozomi Networks reported these vulnerabilities to Automation Direct.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-266-01
www.automationdirect.com/support/software-downloads