Junglewise Threat Intelligence

CVE-2026-60073: AutomationDirect Productivity Suite out-of-bounds read via USB

CVE-2026-60073 · Severity: medium · CVSS 5.9 · Published 2026-07-16

Technologies: AutomationDirect Productivity Suite. Vendors: AutomationDirect.

Executive brief

AutomationDirect Productivity Suite, a software package used to program and manage industrial controllers, is affected by a security flaw. A person with physical access to the system could use a specially prepared USB device to cause the software to crash or leak sensitive system memory. This could disrupt manufacturing operations or expose internal technical data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in AutomationDirect Productivity Suite versions 4.6.2.2 and earlier. The flaw allows a physical attacker with low privileges to control the length of data transmitted to a USB device. By exploiting this, an attacker can trigger a system crash (Denial of Service) or read sensitive kernel memory. The vulnerability is mitigated in version 4.7.0.47. Exploitation requires physical access to the engineering workstation.

Affected products

  • AutomationDirect Productivity Suite <=v4.6.2.2

Timeline

  • 2026-07-16: advisory
  • 2026-07-16: disclosed
  • 2026-07-16: patched: Fixed in version v4.7.0.47

References

Related threats