← Back to home
ICSA-22-202-05  ·  Published 2022-07-21  ·  View on CISA ICS-CERT ↗

AutomationDirect Stride Field I/O

CVSS 9.6 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to obtain user credentials.

CVEs (1)

Remediations

  • AutomationDirect recommends users upgrade the Stride Modbus Field I/O units listed in the affected products section with the firmware associated with the part number. Firmware can be downloaded from the AutomationDirect software downloads page.
  • The modules with a listed B/N number in the affected products section have a firmware update issue and must be returned to AutomationDirect for replacement modules; users can create an RMA on the AutomationDirect website.
  • Automation networks and systems may have built-in password protection schemes, but this is only one step in securing systems. Automation control system networks must incorporate data protection and security measures at least as robust as a typical business computer system. AutomationDirect recommends users of PLCs, HMI products and SCADA systems perform their own network security analysis to determine the proper level of security required for their application.
  • Secure physical access.
  • Isolate and air gap networks when possible.
  • Follow the security considerations in the Automation Direct Security Considerations document.
  • See AutomationDirect product advisory number PA-COM-006 for more information.

Affected Vendors

Automation Direct

Affected Products (14)

Automation Direct · SIO- MB04ADS < 8.4.3.0
Automation Direct · SIO-MB04ADS 5714442222
Automation Direct · SIO-MB04DAS < 8.11.3.0
Automation Direct · SIO-MB04DAS 4714432222
Automation Direct · SIO-MB04RTDS < 8.3.4.0
Automation Direct · SIO-MB04THMS < 8.5.4.0
Automation Direct · SIO-MB04THMS 57141862221
Automation Direct · SIO-MB08ADS-1 < 8.6.3.0
Automation Direct · SIO-MB08ADS-2 < 8.7.3.0
Automation Direct · SIO-MB08THMS < 8.8.4.0
Automation Direct · SIO-MB12CDR < 8.0.4.0
Automation Direct · SIO-MB12CDR 5714442222
Automation Direct · SIO-MB16CDD2 < 8.1.4.0
Automation Direct · SIO-MB16ND3 < 8.2.4.00

Affected Sectors

Commercial Facilities, Critical Manufacturing, Information Technology

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more