Description
AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-08
Scores
CVSS v3
9.8
EPSS
0.0302
EPSS Percentile
86.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-120
Status
published
Products (10)
AutomationDirect/C-more EA9 HMI EA9-RHMI
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T10CL
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T10WCL
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T12CL
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T15CL
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T15CL-R
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T6CL
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T7CL
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T7CL-R
< v6.79
AutomationDirect/C-more EA9 HMI EA9-T8CL
< v6.79
Published
Feb 04, 2025
Tracked Since
Feb 18, 2026