Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.
Solution:
Workaround:
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-202-05 | patch third party advisory us government resource |
https://cdn.automationdirect.com/static/firmware/product_advisory/PA-COM-006.pdf | patch vendor advisory |