CVE-2022-2005
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
31/08/2022
Last modified:
06/09/2022
Description
AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:automationdirect:c-more_ea9-t6cl_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t6cl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t6cl-r_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t6cl-r:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t7cl_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t7cl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t7cl-r_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t7cl-r:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t8cl_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t8cl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t10cl_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t10cl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t10wcl_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) | |
cpe:2.3:h:automationdirect:c-more_ea9-t10wcl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:automationdirect:c-more_ea9-t12cl_firmware:*:*:*:*:*:*:*:* | 6.73 (excluding) |
To consult the complete list of CPE names with products and versions, see this page