AutomationDirect C-More EA9 Stack-Based Buffer Overflow Remote Code Execution Vulnerability

Vulnerability

A stack-based buffer overflow vulnerability allowing remote code execution has been identified in AutomationDirect C-More EA9 programming software, versions through 6.78. The issue arises in the parsing of EAP9 files, where user-supplied data is not properly validated before being copied to a fixed-length stack-based buffer. Exploitation of this vulnerability requires user interaction, such as visiting a malicious page or opening a harmful file.

Impact

Exploitation of this vulnerability leads to memory corruption, allowing remote code execution on the affected system.

Remediation

Users are advised to update C-More EA9 HMI to version 6.79. If an immediate update is not possible, AutomationDirect recommends isolating the engineering workstation from external networks, controlling access to the workstation, implementing application whitelisting, applying endpoint security measures, monitoring and logging activity, hardening the workstation, using secure backup and recovery practices, and conducting regular risk assessments.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
10.0
exploitability
6.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.