Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Automationdirect

First CVE: Nov 13, 2017Active for: 9 yearsTotal CVEs: 35
35.0
VTI Score
Medium

Automationdirect manufactures programmable logic controllers and industrial automation equipment, with a concentrated vulnerability footprint centered on its P-series controller product line and associated firmware. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through memory-safety and authentication-oriented weakness classes including out-of-bounds writes, stack-based buffer overflows, cleartext transmission of sensitive data, and authentication bypass conditions. The exposure pattern reflects the firmware-based nature of these devices and their role in operational technology environments where memory corruption and authentication weakening create direct control-plane risk. While the overall disclosure volume is modest relative to enterprise software vendors, the prominence of this vendor's products in industrial deployments and the severity tendency of its disclosures warrant consistent monitoring. Current exploitation activity, KEV listing status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Automationdirect over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2017
8 years ago
Most Recent CVE
Jan 30, 2025
540 days ago

Products(139 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2003CRITICAL
AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. Th
Aug 31, 20229.130NONO
CVE-2021-32986CRITICAL
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming so
Apr 4, 20229.830NONO
CVE-2021-32984CRITICAL
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs wi
Apr 4, 20229.830NONO
CVE-2020-10921CRITICAL
This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required t
Jul 23, 20209.830NONO
CVE-2021-32980CRITICAL
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to th
Apr 4, 20229.829NONO
CVE-2024-24963CRITICAL
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network
May 28, 20249.828NONO
CVE-2024-23601CRITICAL
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution.
May 28, 20249.828NONO
CVE-2024-21785CRITICAL
A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted series of network requests can
May 28, 20249.828NONO
CVE-2024-24962CRITICAL
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network
May 28, 20249.827NONO
CVE-2024-24955HIGH
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted networ
May 28, 20248.227NONO
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
63%
34%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (14.3%)
Network30 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (97.1%)
High1 (2.9%)
Unknown0 (0.0%)
User Interaction
None30 (85.7%)
Unknown0 (0.0%)
Required5 (14.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None35 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Automationdirect.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Automationdirect — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Automationdirect's Products

View all 3 CNAs →

Top CWEs