CVE-2022-2004 – AutomationDirect DirectLOGIC with Ethernet Communication Uncontrolled Resource Consumption
https://notcve.org/view.php?id=CVE-2022-2004
AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72; AutomationDirect DirectLOGIC es vulnerable a un paquete especialmente diseñado puede ser enviado continuamente al PLC para evitar el acceso de DirectSoft y otros dispositivos, causando una condición de denegación de servicio. Este problema afecta a: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versiones anteriores a 2.72; D0-06DD2 versiones anteriores a 2.72; D0-06DR versiones anteriores a 2.72; D0-06DA versiones anteriores a 2.72; D0-06AR versiones anteriores a 2.72; D0-06AA versiones anteriores a 2.72; D0-06DD1-D versiones anteriores a 2.72; D0-06DD2-D versiones anteriores a 2.72; D0-06DR-D versiones anteriores a 2.72; • https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-03 • CWE-400: Uncontrolled Resource Consumption •
CVE-2022-2003 – AutomationDirect DirectLOGIC with Serial Communication Cleartext Transmission
https://notcve.org/view.php?id=CVE-2022-2003
AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72; AutomationDirect DirectLOGIC es vulnerable a un mensaje serie específicamente diseñado para el puerto serie de la CPU que causará que el PLC responda con la contraseña del PLC en texto sin cifrar. Esto podría permitir a un atacante acceder y realizar cambios no autorizados. Este problema afecta a: CPUs de la serie D0-06 de AutomationDirect D0-06DD1 versiones anteriores a 2.72; D0-06DD2 versiones anteriores a 2.72; D0-06DR versiones anteriores a 2.72; D0-06DA versiones anteriores a 2.72; D0-06AR versiones anteriores a 2.72; D0-06AA versiones anteriores a 2.72; D0-06DD1-D versiones anteriores a 2.72; D0-06DD2-D versiones anteriores a 2.72; D0-06DR-D versiones anteriores a 2.72 • https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-02 https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-03 • CWE-319: Cleartext Transmission of Sensitive Information •