CVE-2025-55069 Details
Description
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys.
A vulnerability has been identified in the Click Plus PLC firmware version 3.60, where a predictable seed in the pseudo-random number generator compromises the security of generated private keys. This vulnerability allows for the potential manipulation of cryptographic operations, as the predictability of the seed can be exploited to reproduce random values used in key generation.
Users are advised to update the Click Plus PLC firmware to version 3.80. If an immediate update is not possible, it is recommended to isolate the PLC from external networks, restrict access to authorized personnel, and use secure internal communications.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2025CISA-ADP
Assessed Sep 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.automationdirect.com/support/software-downloads | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-266-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-337 | Predictable Seed in Pseudo-Random Number Generator (PRNG) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AutomationDirect Click Plus C0-0x CPU | < 3.71 |
CPE
Remediation
| |
| AutomationDirect Click Plus C0-1x CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Click Plus C2-x CPU | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | New CVE Received | [email protected] |
Volerion