AutomationDirect DirectLOGIC with Ethernet Communication Uncontrolled Resource Consumption
CVE-2022-2004
7.5HIGH
What is CVE-2022-2004?
AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;
Affected Version(s)
DirectLOGIC D0-06 series CPUs D0-06DD1 < 2.72
DirectLOGIC D0-06 series CPUs D0-06DD2 < 2.72
DirectLOGIC D0-06 series CPUs D0-06DR < 2.72
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sam Hanson of Dragos reported this vulnerability to CISA.