Improper access control in AutomationDirect products - CVE-2024-22187
Published: May 24, 2024
Productivity 3000 P3-550E CPU
Productivity 3000 P3-550 CPU
Productivity 3000 P3-530 CPU
Productivity 2000 P2-550 CPU
Productivity 1000 P1-550 CPU
Productivity 1000 P1-540 CPU
AutomationDirect
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the write-what-where issue in the Programming Software Connection Remote Memory Diagnostics functionality. A remote attacker can bypass implemented security restrictions and cause arbitrary write.