CVE-2025-59484 Details
Description
The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software uses an insecure implementation of the RSA encryption algorithm.
A vulnerability has been identified in AutomationDirect Click Plus PLC firmware version 3.60, where an insecure implementation of the RSA encryption algorithm is used. This vulnerability allows for potential exploitation due to the reliance on a broken cryptographic algorithm.
Users are advised to update the Click Plus PLC firmware to version 3.80. If an immediate update is not possible, it is recommended to isolate the PLC from external networks, restrict access to authorized personnel, and use secure internal communications. Additionally, maintain secure backups of the PLC's configurations and regularly review system logs for any suspicious activity.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2025CISA-ADP
Assessed Sep 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.automationdirect.com/support/software-downloads | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-266-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AutomationDirect CLICK PLUS | < 3.71 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | New CVE Received | [email protected] |
Volerion