Junglewise Threat Intelligence

CVE-2026-57896: AutomationDirect Productivity Suite out-of-bounds read via IOCTL

CVE-2026-57896 · Severity: medium · CVSS 6.1 · Published 2026-07-16

Technologies: AutomationDirect Productivity Suite. Vendors: AutomationDirect.

Executive brief

AutomationDirect Productivity Suite is a software package used to program and manage industrial programmable logic controllers (PLCs). A vulnerability in this suite could allow a local user to cause the software to crash or leak limited pieces of sensitive information. This could disrupt manufacturing operations or lead to unauthorized access to technical details about the industrial control environment.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in AutomationDirect Productivity Suite versions 4.6.2.2 and prior. The flaw is triggered when the application processes a specially crafted I/O Control (IOCTL) request, leading to kernel memory corruption. A local attacker with low privileges can exploit this to disclose sensitive kernel memory or cause a denial-of-service (system instability/crash). The vulnerability is addressed in version 4.7.0.47.

Affected products

  • AutomationDirect Productivity Suite <=v4.6.2.2

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats