9.6

CVE-2022-2485

Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AutomationdirectSio-mb04rtds Firmware Version < 8.3.4.0
   AutomationdirectSio-mb04rtds Version-
AutomationdirectSio-mb04ads Firmware Version < 8.4.3.0
   AutomationdirectSio-mb04ads Version-
AutomationdirectSio-mb04thms Firmware Version < 8.5.4.0
   AutomationdirectSio-mb04thms Version-
AutomationdirectSio-mb08ads-1 Firmware Version < 8.6.3.0
   AutomationdirectSio-mb08ads-1 Version-
AutomationdirectSio-mb08ads-2 Firmware Version < 8.7.3.0
   AutomationdirectSio-mb08ads-2 Version-
AutomationdirectSio-mb08thms Firmware Version < 8.8.4.0
   AutomationdirectSio-mb08thms Version-
AutomationdirectSio-mb04das Firmware Version < 8.11.3.0
   AutomationdirectSio-mb04das Version-
AutomationdirectSio-mb12cdr Firmware Version < 8.0.4.0
   AutomationdirectSio-mb12cdr Version-
AutomationdirectSio-mb16cdd2 Firmware Version < 8.1.4.0
   AutomationdirectSio-mb16cdd2 Version-
AutomationdirectSio-mb16nd3 Firmware Version < 8.2.4.0
   AutomationdirectSio-mb16nd3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.295
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ics-cert@hq.dhs.gov 9.6 2.8 6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.