Back

HIGH

AutomationDirect C-MORE EA9 HMI Path Traversal

Published Mar 26, 2024

Description

There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.

Affected products

Remediation

Vendor solution

AutomationDirect recommends that users update C-MORE EA9 HMI to V6.78 https://www.automationdirect.com/support/software-downloads .

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Mar 26, 2024
Updated Aug 8, 2024
Reserved Feb 5, 2024

CISA Vulnrichment

Updated Aug 8, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Mar 26, 2024
Updated Aug 8, 2024

GitHub

No data