PatchSiren cyber security CVE debrief
CVE-2025-58473 AutomationDirect CVE debrief
CVE-2025-58473 is a medium-severity denial-of-service issue affecting AutomationDirect CLICK PLUS firmware 3.60 on the C2-03CPU-2 device. According to the CISA CSAF advisory published on 2025-09-23, an unauthenticated attacker can exhaust available Click Programming Software device sessions, disrupting availability. AutomationDirect recommends updating to firmware V3.80 and using compensating controls until patching is complete.
- Vendor
- AutomationDirect
- Product
- CLICK PLUS C0-0x CPU firmware
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-09-23
- Original CVE updated
- 2025-09-23
- Advisory published
- 2025-09-23
- Advisory updated
- 2025-09-23
Who should care
OT/ICS operators, control-system engineers, system integrators, and defenders responsible for AutomationDirect CLICK PLUS PLCs running affected firmware, especially deployments exposed to broader internal networks.
Technical summary
The advisory describes an improper resource shutdown/release condition in CLICK PLUS firmware 3.60 that can be triggered without authentication. The documented impact is availability-only: an attacker can consume all available device sessions of the Click Programming Software, resulting in denial of service. The supplied CVSS vector is 3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (5.9, Medium).
Defensive priority
Medium overall; prioritize faster action for any affected PLCs reachable from corporate or plant networks.
Recommended defensive actions
- Upgrade affected CLICK PLUS firmware to V3.80 as recommended by AutomationDirect.
- If immediate upgrading is not possible, isolate the PLC from external networks and limit connectivity to trusted internal or air-gapped systems.
- Restrict physical and logical access to authorized personnel only.
- Use application whitelisting and host/network controls to prevent unauthorized access attempts against engineering workstations and related systems.
- Enable and review logs and monitoring for unusual session exhaustion or repeated connection attempts.
- Maintain tested backups of PLC configurations and validate recovery procedures before changes are made.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-266-01 and the supplied source item metadata, both published/modified on 2025-09-23. The source explicitly states the affected device/firmware, the unauthenticated denial-of-service impact, and the vendor-recommended upgrade to V3.80. No additional exploitation details are included beyond the supplied advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-58473 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-58473
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-58473 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-58473
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-266-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-266-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.