AutomationDirect DirectLOGIC with Ethernet Communication Uncontrolled Resource Consumption
CVE-2022-2004

7.5HIGH

Key Information:

Vendor
CVE Published:
31 August 2022

What is CVE-2022-2004?

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

Affected Version(s)

DirectLOGIC D0-06 series CPUs D0-06DD1 < 2.72

DirectLOGIC D0-06 series CPUs D0-06DD2 < 2.72

DirectLOGIC D0-06 series CPUs D0-06DR < 2.72

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sam Hanson of Dragos reported this vulnerability to CISA.
.