Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · automationdirect

automationdirect

· 12 Critical

Total CVEs

35

Critical

12

Products

139

Search All CVEs →

35

Products (139)

p3-550e firmware15 CVEsp3-550e15 CVEsp3-5309 CVEsp1-5409 CVEsp2-550 firmware9 CVEsp3-5509 CVEsp3-530 firmware9 CVEsp3-550 firmware9 CVEsp2-5509 CVEsp1-550 firmware9 CVEsp1-5509 CVEsp1-540 firmware9 CVEsc-more ea9-t12cl firmware6 CVEsc-more ea9-t15cl6 CVEsc-more ea9-t15cl-r6 CVEsc-more ea9-t15cl firmware6 CVEsc-more ea9-t15cl-r firmware6 CVEsc-more ea9-t6cl6 CVEsc-more ea9-t6cl-r6 CVEsc-more ea9-t6cl-r firmware6 CVEsc-more ea9-t6cl firmware6 CVEsc-more ea9-t8cl6 CVEsc-more ea9-t8cl firmware6 CVEsc-more ea9-t10cl6 CVEsc-more ea9-t10cl firmware6 CVEsc-more ea9-t10wcl6 CVEsc-more ea9-t10wcl firmware6 CVEsc-more ea9-t12cl6 CVEsc0-12dd1e-2-d firmware5 CVEsc0-12dd1e-d5 CVEsc0-12dd1e-d firmware5 CVEsc0-12dd2e-1-d5 CVEsc0-12dd2e-1-d firmware5 CVEsc0-12dd2e-2-d5 CVEsc0-12dd2e-2-d firmware5 CVEsc0-12dd2e-d5 CVEsc0-12dd2e-d firmware5 CVEsc0-12dre-1-d5 CVEsc0-12dre-1-d firmware5 CVEsc0-12dre-2-d5 CVEsc0-12dre-2-d firmware5 CVEsc0-12dre-d5 CVEsc0-12dre-d firmware5 CVEsc0-10dd1e-d firmware5 CVEsc-more ea9-rhmi5 CVEsc-more ea9-rhmi firmware5 CVEsc-more hmi ea9 firmware5 CVEsc0-10are-d5 CVEsc0-10are-d firmware5 CVEsc0-10dd1e-d5 CVEsc0-10dd2e-d5 CVEsc0-10dd2e-d firmware5 CVEsc0-10dre-d5 CVEsc0-10dre-d firmware5 CVEsc0-11are-d5 CVEsc0-11are-d firmware5 CVEsc0-11dd1e-d5 CVEsc0-11dd1e-d firmware5 CVEsc0-11dd2e-d5 CVEsc0-11dd2e-d firmware5 CVEsc0-11dre-d5 CVEsc0-11dre-d firmware5 CVEsc0-12are-1-d5 CVEsc0-12are-1-d firmware5 CVEsc0-12are-2-d5 CVEsc0-12are-2-d firmware5 CVEsc0-12are-d5 CVEsc0-12are-d firmware5 CVEsc0-12dd1e-1-d5 CVEsc0-12dd1e-1-d firmware5 CVEsc0-12dd1e-2-d5 CVEsea9-pgmsw5 CVEsea9-rhmi5 CVEsea9-t10cl5 CVEsea9-t10wcl5 CVEsea9-t12cl5 CVEsea9-t15cl5 CVEsea9-t15cl-r5 CVEsea9-t6cl5 CVEsea9-t6cl-r5 CVEsea9-t7cl5 CVEsea9-t7cl-r5 CVEsea9-t8cl5 CVEsc-more ea9-t7cl3 CVEsc-more ea9-t7cl-r3 CVEsc-more ea9-t7cl-r firmware3 CVEsc-more ea9-t7cl firmware3 CVEsd0-06dr2 CVEsd0-06dr-d2 CVEsd0-06dr-d firmware2 CVEsd0-06dr firmware2 CVEsd0-06dd22 CVEsd0-06dd2-d2 CVEsd0-06dd2-d firmware2 CVEsd0-06dd2 firmware2 CVEsc-more ea9-pgmsw2 CVEsc-more ea9-pgmsw firmware2 CVEsd0-06aa2 CVEsd0-06aa firmware2 CVEsd0-06ar2 CVEsd0-06ar firmware2 CVEsd0-06da2 CVEsd0-06da firmware2 CVEsd0-06dd12 CVEsd0-06dd1-d2 CVEsd0-06dd1-d firmware2 CVEsd0-06dd1 firmware2 CVEsc-more plc1 CVEsc-more micro firmware1 CVEsc-more micro1 CVEssio-mb08thms firmware1 CVEssio-mb08thms1 CVEssio-mb08ads-2 firmware1 CVEssio-mb08ads-21 CVEsc-more ea9-rhi firmware1 CVEsc-more ea9-rhi1 CVEsclick plc firmware1 CVEssio-mb04ads1 CVEssio-mb04ads firmware1 CVEssio-mb04das1 CVEssio-mb04das firmware1 CVEssio-mb04rtds1 CVEssio-mb04rtds firmware1 CVEssio-mb04thms1 CVEssio-mb04thms firmware1 CVEssio-mb08ads-11 CVEssio-mb08ads-1 firmware1 CVEssio-mb12cdr1 CVEssio-mb12cdr firmware1 CVEssio-mb16cdd21 CVEssio-mb16cdd2 firmware1 CVEssio-mb16nd31 CVEssio-mb16nd3 firmware1 CVEssl-soft solo temperature controller1 CVEssl-soft solo temperature controller firmware1 CVEsgs drives1 CVEsgs drives fimware1 CVEsclick plc1 CVEsc-more plc firmware1 CVEs

Recent Vulnerabilities

View all 35
CVE-2024-11611

AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EAP9 files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24774.

CVE-2024-11610

AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EAP9 files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24773.

CVE-2024-11609

AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EAP9 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24772.

CVE-2024-24963CRITICAL 9.8

A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.This CVE tracks the stack-based buffer overflow that occurs at offset `0xb6e84` of v1.2.10.9 of the P3-550E firmware.

CVE-2024-24962CRITICAL 9.8

A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.This CVE tracks the stack-based buffer overflow that occurs at offset `0xb6e98` of v1.2.10.9 of the P3-550E firmware.

CVE-2024-24959HIGH 8.2

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks the arbitrary null-byte write vulnerability located in firmware 1.2.10.9 of the P3-550E at offset `0xb6c18`.

CVE-2024-24958HIGH 8.2

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks the arbitrary null-byte write vulnerability located in firmware 1.2.10.9 of the P3-550E at offset `0xb6bdc`.

CVE-2024-24957HIGH 8.2

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks the arbitrary null-byte write vulnerability located in firmware 1.2.10.9 of the P3-550E at offset `0xb6aa4`.

CVE-2024-24956HIGH 8.2

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks the arbitrary null-byte write vulnerability located in firmware 1.2.10.9 of the P3-550E at offset `0xb6a38`.

CVE-2024-24955HIGH 8.2

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks the arbitrary null-byte write vulnerability located in firmware 1.2.10.9 of the P3-550E at offset `0xb69fc`.

CVE-2024-24954HIGH 8.2

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks the arbitrary null-byte write vulnerability located in firmware 1.2.10.9 of the P3-550E at offset `0xb69c8`.

CVE-2024-24947HIGH 8.2

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap corruption that occurs at offset `0xb68c4` of version 1.2.10.9 of the P3-550E firmware, which occurs when a call to `memset` relies on an attacker-controlled length value and corrupts any trailing heap allocations.

CVE-2024-24946HIGH 8.2

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap corruption that occurs at offset `0xb686c` of version 1.2.10.9 of the P3-550E firmware, which occurs when a call to `memset` relies on an attacker-controlled length value and corrupts any trailing heap allocations.

CVE-2024-24851HIGH 7.5

A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.

CVE-2024-23601CRITICAL 9.8

A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-23315HIGH 7.5

A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can send an unauthenticated packet to trigger this vulnerability.

CVE-2024-22187CRITICAL 9.1

A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to trigger this vulnerability.

CVE-2024-21785CRITICAL 9.8

A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted series of network requests can lead to unauthorized access. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-2485CRITICAL 9.6

Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

CVE-2022-2006HIGH 7.8

AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code during the installation process. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;

CVE-2022-2005HIGH 7.5

AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;

CVE-2022-2004HIGH 7.5

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

CVE-2022-2003HIGH 7.7

AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

CVE-2021-32986CRITICAL 9.8

After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.

CVE-2021-32984CRITICAL 9.8

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.