Back to Database
Status published
Medium
CVE-2024-25138
AutomationDirect C-MORE EA9 HMI Plaintext Storage of a Password
Vulnerability Description
In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25138
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Tomer Goldschmidt of Claroty Research - Team82 reported these vulnerabilities to CISA.
More from AutomationDirect
View All →CVE-2025-67652
AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password
Medium
6.1
CVE-2025-62688
AutomationDirect Productivity Suite Incorrect Permission Assignment for Critical Resource
Medium
6.9
CVE-2025-62498
AutomationDirect Productivity Suite Relative Path Traversal
High
8.6
CVE-2025-61977
AutomationDirect Productivity Suite Weak Password Recovery Mechanism for Forgotten Password
High
7.3
CVE-2025-61934
AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327
Critical
9.3
Affected Vendor
AutomationDirect
View all reports →Affected Software
C-MORE EA9 HMI EA9-T6CL, C-MORE EA9 HMI EA9-T7CL, C-MORE EA9 HMI EA0-T7CL-R, C-MORE EA9 HMI EA9-T8CL, C-MORE EA9 HMI EA9-T10CL, C-MORE EA9 HMI EA9-T10WCL, C-MORE EA9 HMI EA9-T12CL, C-MORE EA9 HMI EA9-T15CL, C-MORE EA9 HMI EA9-T15CL-R, C-MORE EA9 HMI EA9-RHMI, C-MORE EA9 HMI EA9-PGMSW
Vulnerable Versions:
0
Timeline
Official Publish:
March 26th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N