Hard-Coded Cryptographic Key Vulnerability in Click Plus PLC by AutomationDirect
CVE-2025-58069
6.9MEDIUM
What is CVE-2025-58069?
A security flaw has been identified in firmware version 3.60 of the Click Plus PLC, where a hard-coded AES cryptographic key is utilized. This design oversight enables unauthorized access to sensitive session messages, posing significant risks to the system's integrity and security. Proper measures should be undertaken to address this vulnerability and protect sensitive data from potential exploitation.
Affected Version(s)
CLICK PLUS C0-0x CPU firmware 0
CLICK PLUS C0-1x CPU firmware 0
CLICK PLUS C2-x CPU firmware 0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Luca Borzacchiello and Diego Zaffaroni of Nozomi Networks reported these vulnerabilities to Automation Direct.