// For flags

CVE-2022-2485

AutomationDirect Stride Field I/O Cleartext Transmission of Sensitive Information

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

Cualquier intento (bueno o malo) de iniciar sesión en AutomationDirect Stride Field I/O con un navegador web puede hacer que el dispositivo responda con su contraseña en los paquetes de comunicación

*Credits: Byron Chaney of Accenture Security reported this vulnerability to CISA.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-19 CVE Reserved
  • 2022-08-31 CVE Published
  • 2024-03-23 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Automationdirect
Search vendor "Automationdirect"
Sio-mb04rtds Firmware
Search vendor "Automationdirect" for product "Sio-mb04rtds Firmware"
< 8.3.4.0
Search vendor "Automationdirect" for product "Sio-mb04rtds Firmware" and version " < 8.3.4.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb04rtds
Search vendor "Automationdirect" for product "Sio-mb04rtds"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb04ads Firmware
Search vendor "Automationdirect" for product "Sio-mb04ads Firmware"
< 8.4.3.0
Search vendor "Automationdirect" for product "Sio-mb04ads Firmware" and version " < 8.4.3.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb04ads
Search vendor "Automationdirect" for product "Sio-mb04ads"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb04thms Firmware
Search vendor "Automationdirect" for product "Sio-mb04thms Firmware"
< 8.5.4.0
Search vendor "Automationdirect" for product "Sio-mb04thms Firmware" and version " < 8.5.4.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb04thms
Search vendor "Automationdirect" for product "Sio-mb04thms"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb08ads-1 Firmware
Search vendor "Automationdirect" for product "Sio-mb08ads-1 Firmware"
< 8.6.3.0
Search vendor "Automationdirect" for product "Sio-mb08ads-1 Firmware" and version " < 8.6.3.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb08ads-1
Search vendor "Automationdirect" for product "Sio-mb08ads-1"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb08ads-2 Firmware
Search vendor "Automationdirect" for product "Sio-mb08ads-2 Firmware"
< 8.7.3.0
Search vendor "Automationdirect" for product "Sio-mb08ads-2 Firmware" and version " < 8.7.3.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb08ads-2
Search vendor "Automationdirect" for product "Sio-mb08ads-2"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb08thms Firmware
Search vendor "Automationdirect" for product "Sio-mb08thms Firmware"
< 8.8.4.0
Search vendor "Automationdirect" for product "Sio-mb08thms Firmware" and version " < 8.8.4.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb08thms
Search vendor "Automationdirect" for product "Sio-mb08thms"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb04das Firmware
Search vendor "Automationdirect" for product "Sio-mb04das Firmware"
< 8.11.3.0
Search vendor "Automationdirect" for product "Sio-mb04das Firmware" and version " < 8.11.3.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb04das
Search vendor "Automationdirect" for product "Sio-mb04das"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb12cdr Firmware
Search vendor "Automationdirect" for product "Sio-mb12cdr Firmware"
< 8.0.4.0
Search vendor "Automationdirect" for product "Sio-mb12cdr Firmware" and version " < 8.0.4.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb12cdr
Search vendor "Automationdirect" for product "Sio-mb12cdr"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb16cdd2 Firmware
Search vendor "Automationdirect" for product "Sio-mb16cdd2 Firmware"
< 8.1.4.0
Search vendor "Automationdirect" for product "Sio-mb16cdd2 Firmware" and version " < 8.1.4.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb16cdd2
Search vendor "Automationdirect" for product "Sio-mb16cdd2"
--
Safe
Automationdirect
Search vendor "Automationdirect"
Sio-mb16nd3 Firmware
Search vendor "Automationdirect" for product "Sio-mb16nd3 Firmware"
< 8.2.4.0
Search vendor "Automationdirect" for product "Sio-mb16nd3 Firmware" and version " < 8.2.4.0"
-
Affected
in Automationdirect
Search vendor "Automationdirect"
Sio-mb16nd3
Search vendor "Automationdirect" for product "Sio-mb16nd3"
--
Safe