AutomationDirect C-more EA9 HMI Cleartext Transmission
Published Aug 31, 2022
7.5
HIGHCVSS 3.1
EPSS 0.52%
Description
AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;
Affected products
-
- Version EA9-PGMSWStatusaffectedConstraints<6.73
- Version EA9-RHMIStatusaffectedConstraints<6.73
- Version EA9-T10CLStatusaffectedConstraints<6.73
- Version EA9-T10WCLStatusaffectedConstraints<6.73
- Version EA9-T12CLStatusaffectedConstraints<6.73
- Version EA9-T15CLStatusaffectedConstraints<6.73
- Version EA9-T6CLStatusaffectedConstraints<6.73
- Version EA9-T6CL-RStatusaffectedConstraints<6.73
- Version EA9-T7CLStatusaffectedConstraints<6.73
- Version EA9-T7CL-RStatusaffectedConstraints<6.73
- Version EA9-T8CLStatusaffectedConstraints<6.73
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AutomationDirect | C-more EA9 | n/a |
|
Configuration 1
- < 6.73
Running on/with
- n/a
Configuration 2
- < 6.73
Running on/with
- n/a
Configuration 3
- < 6.73
Running on/with
- n/a
Configuration 4
- < 6.73
Running on/with
- n/a
Configuration 5
- < 6.73
Running on/with
- n/a
Configuration 6
- < 6.73
Running on/with
- n/a
Configuration 7
- < 6.73
Running on/with
- n/a
Configuration 8
- < 6.73
Running on/with
- n/a
Configuration 9
- < 6.73
Running on/with
- n/a
Configuration 10
- < 6.73
Running on/with
- n/a
Configuration 11
- < 6.73
Running on/with
- n/a
Configuration 12
- < 6.73
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
AutomationDirect recommends users upgrade to firmware Version 6.73 or later, which supports TLS security options for the webserver.
While automation networks and systems have built-in password protection schemes, this is only one step in securing the affected systems. Automation control system networks must incorporate data protection and security measures at least as robust as a typical business computer system. AutomationDirect recommends users of PLCs, HMI products, and other SCADA system products perform independent network security analysis to determine the proper level of security required for the application.
AutomationDirect has identified the following mitigations for instances where systems cannot be upgraded to Version 6.73 or later:
The Webserver feature can be disabled on the HMI using the programming software. Place the HMI panel behind a VPN: Access to and from critical control system assets in the modern environment is usually LAN based, but still should be considered remote if the operator is traversing across different networks. virtual private networking (VPN) is often considered the best approach in securing trans-network communication.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 16, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.52% (0.00524) | 42.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00425) | 33.73th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00053) | 13.86th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.14% (0.00144) | 51.82th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.14% (0.00144) | 49.02th | v3 (v2023.03.01) |
| Sep 7, 2023 | 0.13% (0.00132) | 47.65th | v3 (v2023.03.01) |
| Aug 1, 2023 | 0.09% (0.00094) | 38.97th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00087) | 35.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 1, 2022 | 0.89% (0.00885) | 26.13th | v2 (v2022.01.01) |
References (1)
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-01 x_refsource_CONFIRMPatchThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-167-01 | x_refsource_CONFIRMPatchThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.