CVE Database
/

CVE-2022-2485

Back to search

CVE-2022-2485

Published: Aug 31, 2022

Modified: Apr 16, 2025

PUBLISHED

CVSS v3.1

9.6

CRITICAL

Description

Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

VendorProductVersions

AutomationDirect

SIO-MB04RTDS

affected
unspecified - < 8.3.4.0

AutomationDirect

SIO- MB04ADS

affected
unspecified - < 8.4.3.0

AutomationDirect

SIO-MB04THMS

affected
unspecified - < 8.5.4.0

AutomationDirect

SIO-MB08ADS-1

affected
unspecified - < 8.6.3.0

AutomationDirect

SIO-MB08ADS-2

affected
unspecified - < 8.7.3.0

AutomationDirect

SIO-MB08THMS

affected
unspecified - < 8.8.4.0

AutomationDirect

SIO-MB04DAS

affected
unspecified - < 8.11.3.0

AutomationDirect

SIO-MB12CDR

affected
unspecified - < 8.0.4.0

AutomationDirect

SIO-MB16CDD2

affected
unspecified - < 8.1.4.0

AutomationDirect

SIO-MB16ND3

affected
unspecified - < 8.2.4.00

AutomationDirect

SIO-MB12CDR

affected
batch number (B/N) 5714442222

AutomationDirect

SIO-MB04ADS

affected
B/N 5714442222

AutomationDirect

SIO-MB04THMS

affected
B/N 57141862221

AutomationDirect

SIO-MB04DAS

affected
B/N 4714432222

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now