Executive brief
AutomationDirect Productivity Suite, a software package used to program and manage industrial controllers, is affected by a security flaw. A person with physical access to the system could use a specially prepared USB device to cause the software to crash or leak sensitive system memory. This could disrupt manufacturing operations or expose internal technical data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in AutomationDirect Productivity Suite versions 4.6.2.2 and earlier. The flaw allows a physical attacker with low privileges to control the length of data transmitted to a USB device. By exploiting this, an attacker can trigger a system crash (Denial of Service) or read sensitive kernel memory. The vulnerability is mitigated in version 4.7.0.47. Exploitation requires physical access to the engineering workstation.
Affected products
- AutomationDirect Productivity Suite <=v4.6.2.2
Timeline
- 2026-07-16: advisory
- 2026-07-16: disclosed
- 2026-07-16: patched: Fixed in version v4.7.0.47