Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2025-0960

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.
0
Attacker Value
Unknown

CVE-2024-25138

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.
0
Attacker Value
Unknown

CVE-2024-25137

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer on the stack which may lead to a stack overflow. The result of this stack-based buffer overflow can lead to denial-of-service conditions.
0
Attacker Value
Unknown

CVE-2024-25136

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.
0