AutomationDirect C-more EA9 HMI Buffer Overflow Vulnerability Allowing Denial-of-Service and Remote Code Execution

Vulnerability

A buffer copy vulnerability without proper input size checks has been identified in AutomationDirect C-more EA9 HMI versions through 6.79. This vulnerability allows attackers to bypass bounds checks, potentially leading to a denial-of-service condition or remote code execution on the affected device.

Impact

Exploitation of this vulnerability could cause a denial-of-service condition or allow for remote code execution on the affected device.

Remediation

Users are advised to update the C-more EA9 HMI software and firmware to version 6.80. If an immediate update is not possible, consider isolating the HMI workstation from external networks, restricting access to authorized personnel, implementing application whitelisting, applying endpoint security measures, monitoring and logging activity, using secure backup and recovery practices, and conducting regular risk assessments. For more information, see the AutomationDirect security advisory.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
7.0
remediation
7.9
relevance
0.0
threat
0.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.