6.1
CVE-2025-67652
- EPSS 0.1%
- Veröffentlicht 22.01.2026 22:17:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password
An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type of exploitation, leaving sensitive information more vulnerable.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAutomationDirect
≫
Produkt
CLICK Programmable Logic Controller
Default Statusunaffected
Version
C0-0x
Status
affected
Version
C0-1x
Status
affected
Version
C2-x
Status
affected
Version
V3.90
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.011 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ics-cert@hq.dhs.gov | 6.1 | 1.8 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-261 Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-02
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-022-02.json