← Back to home
ICSA-22-167-01  ·  Published 2022-06-16  ·  View on CISA ICS-CERT ↗

AutomationDirect C-More EA9 HMI

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could cause a loss of sensitive information and the ability to run code execution with elevated privileges.

Remediations

  • AutomationDirect recommends users upgrade to firmware Version 6.73 or later, which supports TLS security options for the webserver.
  • While automation networks and systems have built-in password protection schemes, this is only one step in securing the affected systems. Automation control system networks must incorporate data protection and security measures at least as robust as a typical business computer system. AutomationDirect recommends users of PLCs, HMI products, and other SCADA system products perform independent network security analysis to determine the proper level of security required for the application.
  • The Webserver feature can be disabled on the HMI using the programming software.
  • Place the HMI panel behind a VPN: Access to and from critical control system assets in the modern environment is usually LAN based, but still should be considered remote if the operator is traversing across different networks. virtual private networking (VPN) is often considered the best approach in securing trans-network communication.
  • Please refer to the following link for supporting information related to security considerations.
  • For additional information, please refer to AutomationDirect Product Advisory.

Affected Vendors

Automation Direct

Affected Products (12)

Automation Direct · C-more EA9 EA9-T15CL <6.73
Automation Direct · C-more EA9 EA9-T15CL-R <6.73
Automation Direct · C-more EA9 EA9-RHMI <6.73
Automation Direct · C-more EA9 EA9-PGMSW <6.73
Automation Direct · C-more EA9 EA9-T6CL <6.73
Automation Direct · C-more EA9 EA9-T6CL-R <6.73
Automation Direct · C-more EA9 EA9-T7CL <6.73
Automation Direct · C-more EA9 EA9-T7CL-R <6.73
Automation Direct · C-more EA9 EA9-T8CL <6.73
Automation Direct · C-more EA9 EA9-T10CL <6.73
Automation Direct · C-more EA9 EA9-T10WCL <6.73
Automation Direct · C-more EA9 EA9-T12CL <6.73

Affected Sectors

Multiple Sectors

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more