CVE-2025-55069
8.3AutomationDirect · CLICK PLUS PLC
AutomationDirect CLICK PLUS PLCs are vulnerable to predictable pseudo-random number generation, which may allow attackers to compromise the security of generated private keys.
Executive summary
A critical vulnerability in AutomationDirect CLICK PLUS PLC firmware allows for the prediction of random numbers, potentially leading to the compromise of cryptographic keys.
Vulnerability
The device uses a predictable seed for its pseudo-random number generator, which undermines the security of cryptographic processes. This flaw is remotely exploitable and does not require prior authentication, though it relies on user interaction.
Business impact
The compromise of private keys can lead to a complete breakdown of secure communications, allowing unauthorized actors to intercept or manipulate sensitive industrial control traffic. With a CVSS score of 8.3, this high-severity vulnerability poses a significant risk to operational integrity, potentially resulting in unauthorized access to critical infrastructure components and loss of process control.
Remediation
Immediate Action: Update all affected CLICK PLUS PLC firmware to version V3.80 or later as provided by the vendor.
Proactive Monitoring: Monitor network logs for unusual traffic patterns or connection attempts directed at the PLC, particularly from unauthorized or unexpected source IP addresses.
Compensating Controls: Implement strict network isolation by disconnecting the PLC from the internet and corporate LANs, and utilize air-gapped or dedicated internal networks for device management until updates are applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical role of PLCs in industrial environments, immediate patching is essential to prevent potential exploitation. Organizations should prioritize the firmware update to V3.80 and ensure that all affected devices are isolated from untrusted networks until remediation is complete.
Sources
Originally found and disclosed by Luca Borzacchiello and Diego Zaffaroni of Nozomi Networks reported these vulnerabilities to Automation Direct., per the CVE Program record.