PatchSiren cyber security CVE debrief
CVE-2025-0960 AutomationDirect CVE debrief
CVE-2025-0960 is a critical vulnerability in AutomationDirect C-more EA9 HMI products. The advisory says a function’s bounds checks can be skipped, which could let an attacker cause denial of service or achieve remote code execution on affected devices. CISA published the advisory ICSA-25-035-08 on 2025-02-04, and the supplied remediation guidance directs users to update C-MORE EA9 HMI software and firmware to v6.80.
- Vendor
- AutomationDirect
- Product
- C-more EA9 HMI EA9-T6CL
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-04
- Original CVE updated
- 2025-02-04
- Advisory published
- 2025-02-04
- Advisory updated
- 2025-02-04
Who should care
OT and ICS operators using AutomationDirect C-more EA9 HMI devices, HMI/plant engineers, firmware administrators, and security teams responsible for segmented industrial networks should treat this as a high-priority remediation item.
Technical summary
The supplied CSAF advisory identifies 10 EA9 HMI product variants affected at versions <= 6.79, including EA9-T6CL, EA9-T7CL-R, EA9-T7CL, EA9-T8CL, EA9-T10CL, EA9-T10WCL, EA9-T12CL, EA9-T15CL-R, EA9-T15CL, and EA9-RHMI. The issue is described as a bounds-check bypass in a function, with potential denial-of-service and remote code execution impact. The advisory’s CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network-reachable, no-authentication attack conditions and severe confidentiality, integrity, and availability impact.
Defensive priority
Immediate
Recommended defensive actions
- Upgrade affected AutomationDirect C-more EA9 HMI software and firmware to v6.80 as recommended by the vendor.
- If you cannot patch immediately, isolate the HMI workstation from external networks and keep communication on dedicated secure internal or air-gapped systems.
- Restrict physical and logical access to the HMI to authorized personnel only.
- Apply application whitelisting and host-based security controls to limit unauthorized software execution and access.
- Enable logging and monitoring to detect suspicious activity or anomalous HMI behavior.
- Maintain secure backups and test recovery procedures so you can restore configurations quickly if the device is disrupted.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-25-035-08 (initial publication 2025-02-04) and its remediation section. The source data lists 10 affected AutomationDirect C-more EA9 HMI product variants, all at versions <= 6.79, and recommends updating to v6.80. The advisory also provides interim mitigations for environments where immediate updating is not feasible. The included CVE.org and NVD links are official record pointers; the affected version and mitigation details come from the CSAF source item and vendor-linked remediation guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0960 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0960
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0960 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0960
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-035-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.