A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to trigger this vulnerability.
An attacker sends a specially crafted network packet to the port serviced by the Remote Memory Diagnostics module in the control software (Programming Software Connection). This packet allows the attacker to control both the target address and the value written to device memory (hence the write-what-where designation). The lack of any authentication mechanism for this interface means the exploit does not require any credentials.
An attacker can overwrite arbitrary memory areas of the PLC controller, which may lead to disruption or complete shutdown of the industrial process, data integrity damage, and potentially malicious code execution on the device.
Apply patches available from the manufacturer according to references (AutomationDirect advisory SA00036 and Talos Intelligence report TALOS-2024-1940). Until updating, it is recommended to isolate P3-550/P3-550E devices from untrusted networks and restrict network access to diagnostic ports exclusively to authorized engineering stations using firewall or OT network segmentation.
AutomationDirect P3-550E with firmware version 1.2.10.9 and AutomationDirect P3-550 (firmware versions indicated in manufacturer references).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HAutomationdirect P1 540
HWAutomationdirectall versionsAutomationdirect P1 540 Firmware
OSAutomationdirect1.2.10.104.1.1.10Automationdirect P1 550
HWAutomationdirectall versionsAutomationdirect P1 550 Firmware
OSAutomationdirect1.2.10.104.1.1.10Automationdirect P2 550
HWAutomationdirectall versionsAutomationdirect P2 550 Firmware
OSAutomationdirect1.2.10.104.1.1.10Automationdirect P3 530
HWAutomationdirectall versionsAutomationdirect P3 530 Firmware
OSAutomationdirect1.2.10.94.1.1.10Automationdirect P3 550
HWAutomationdirectall versionsAutomationdirect P3 550e
HWAutomationdirectall versionsAutomationdirect P3 550e Firmware
OSAutomationdirect1.2.10.94.1.1.10Automationdirect P3 550 Firmware
OSAutomationdirect1.2.10.94.1.1.10
Related vulnerabilities
Stack-based buffer overflow w AutomationDirect P3-550E — RCE bez uwierzytelnienia
AutomationDirect P3-550E — code injection przez plik scan_lib.bin
AutomationDirect P3-550E — nieusunięty kod debugowania w interfejsie Telnet
Stack-based buffer overflow w AutomationDirect P3-550E — zdalny RCE bez uwierzytelnienia
A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality...