Improper Resource Shutdown Vulnerability in Click Plus C2-03CPU-2 by AutomationDirect
CVE-2025-58473

8.2HIGH

What is CVE-2025-58473?

An improper resource shutdown or release vulnerability has been discovered in the Click Plus C2-03CPU-2 device with firmware version 3.60. This flaw enables unauthenticated attackers to execute a denial-of-service attack by depleting all available sessions of the Click Programming Software, potentially disrupting critical operational processes.

Affected Version(s)

CLICK PLUS C0-0x CPU firmware 0

CLICK PLUS C0-1x CPU firmware 0

CLICK PLUS C2-x CPU firmware 0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luca Borzacchiello and Diego Zaffaroni of Nozomi Networks reported these vulnerabilities to Automation Direct.
.
CVE-2025-58473 : Improper Resource Shutdown Vulnerability in Click Plus C2-03CPU-2 by AutomationDirect