Improper access control in AutomationDirect products - CVE-2024-22187
Published: May 24, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the write-what-where issue in the Programming Software Connection Remote Memory Diagnostics functionality. A remote attacker can bypass implemented security restrictions and cause arbitrary write.
Affected software
Productivity 3000 P3-550 CPU
Productivity 3000 P3-530 CPU
Productivity 2000 P2-550 CPU
Productivity 1000 P1-550 CPU
Productivity 1000 P1-540 CPU
How to mitigate CVE-2024-22187
Productivity 3000 P3-550 CPU - update to 4.2.0
Productivity 3000 P3-530 CPU - update to 4.2.0
Productivity 2000 P2-550 CPU - update to 4.2.0
Productivity 1000 P1-550 CPU - update to 4.2.0
Productivity 1000 P1-540 CPU - update to 4.2.0