AutomationDirect C-more EA9 HMI Uncontrolled Search Path Element
CVE-2022-2006

7.8HIGH

Key Information:

Vendor
CVE Published:
16 June 2022

What is CVE-2022-2006?

AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code during the installation process. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;

Affected Version(s)

C-more EA9 EA9-T6CL < 6.73

C-more EA9 EA9-T6CL-R < 6.73

C-more EA9 EA9-T7CL < 6.73

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sam Hanson of Dragos reported this vulnerability to CISA.
.
CVE-2022-2006 : AutomationDirect C-more EA9 HMI Uncontrolled Search Path Element