CVE-2022-2004

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
31/08/2022
Last modified:
06/09/2022

Description

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:automationdirect:d0-06dd1_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06dd1:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06dd2_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06dd2:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06dr_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06dr:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06da_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06da:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06ar_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06ar:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06aa_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06aa:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06dd1-d_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)
cpe:2.3:h:automationdirect:d0-06dd1-d:-:*:*:*:*:*:*:*
cpe:2.3:o:automationdirect:d0-06dd2-d_firmware:*:*:*:*:*:*:*:* 2.72 (excluding)


References to Advisories, Solutions, and Tools