Filtered by vendor Automationdirect
                         Subscriptions
                    
                    
                
                        Filtered by product Click Plus
                         Subscriptions
                    
                    
                
                    Total
                    7 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2025-58473 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 5.9 Medium | 
| An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programming Software. | ||||
| CVE-2025-55038 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 6.8 Medium | 
| An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC application, authenticated users with low-level access permissions can exploit this vulnerability to read and modify PLC variables beyond their intended authorization level. | ||||
| CVE-2025-59484 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 8.3 High | 
| The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software uses an insecure implementation of the RSA encryption algorithm. | ||||
| CVE-2025-57882 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 5.9 Medium | 
| An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application. | ||||
| CVE-2025-55069 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 8.3 High | 
| A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys. | ||||
| CVE-2025-54855 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 4.2 Medium | 
| Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal credentials stored in clear text. | ||||
| CVE-2025-58069 | 1 Automationdirect | 1 Click Plus | 2025-09-25 | 5.3 Medium | 
| The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session. | ||||
                            
                                
                                
                                    Page 1 of 1.