CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-22187

CVSS 9.1v3.1pub. 2024-05-28upd. 2025-02-12

A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to trigger this vulnerability.

🤖 AI Analysis
How it works

An attacker sends a specially crafted network packet to the port serviced by the Remote Memory Diagnostics module in the control software (Programming Software Connection). This packet allows the attacker to control both the target address and the value written to device memory (hence the write-what-where designation). The lack of any authentication mechanism for this interface means the exploit does not require any credentials.

Impact

An attacker can overwrite arbitrary memory areas of the PLC controller, which may lead to disruption or complete shutdown of the industrial process, data integrity damage, and potentially malicious code execution on the device.

Mitigation & patch

Apply patches available from the manufacturer according to references (AutomationDirect advisory SA00036 and Talos Intelligence report TALOS-2024-1940). Until updating, it is recommended to isolate P3-550/P3-550E devices from untrusted networks and restrict network access to diagnostic ports exclusively to authorized engineering stations using firewall or OT network segmentation.

Who is affected

AutomationDirect P3-550E with firmware version 1.2.10.9 and AutomationDirect P3-550 (firmware versions indicated in manufacturer references).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Automationdirect P1 540

    HW
    Automationdirect
    all versions
  • Automationdirect P1 540 Firmware

    OS
    Automationdirect
    1.2.10.104.1.1.10
  • Automationdirect P1 550

    HW
    Automationdirect
    all versions
  • Automationdirect P1 550 Firmware

    OS
    Automationdirect
    1.2.10.104.1.1.10
  • Automationdirect P2 550

    HW
    Automationdirect
    all versions
  • Automationdirect P2 550 Firmware

    OS
    Automationdirect
    1.2.10.104.1.1.10
  • Automationdirect P3 530

    HW
    Automationdirect
    all versions
  • Automationdirect P3 530 Firmware

    OS
    Automationdirect
    1.2.10.94.1.1.10
  • Automationdirect P3 550

    HW
    Automationdirect
    all versions
  • Automationdirect P3 550e

    HW
    Automationdirect
    all versions
  • Automationdirect P3 550e Firmware

    OS
    Automationdirect
    1.2.10.94.1.1.10
  • Automationdirect P3 550 Firmware

    OS
    Automationdirect
    1.2.10.94.1.1.10
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-24963CRITICAL9.8PL ✓same product

Stack-based buffer overflow w AutomationDirect P3-550E — RCE bez uwierzytelnienia

CVE-2024-23601CRITICAL9.8PL ✓same product

AutomationDirect P3-550E — code injection przez plik scan_lib.bin

CVE-2024-21785CRITICAL9.8PL ✓same product

AutomationDirect P3-550E — nieusunięty kod debugowania w interfejsie Telnet

CVE-2024-24962CRITICAL9.8PL ✓same product

Stack-based buffer overflow w AutomationDirect P3-550E — zdalny RCE bez uwierzytelnienia

CVE-2024-24946HIGH8.2same product

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality...