Executive brief
AutomationDirect Productivity Suite, a software package used to program and manage industrial controllers, is affected by a memory handling vulnerability. A local attacker with access to the system could exploit this flaw to crash the software or access sensitive information stored in memory. This could lead to operational downtime in manufacturing environments or the exposure of proprietary configuration data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the AutomationDirect Productivity Suite due to improper validation of IOCTL (Input/Output Control) requests. A local attacker with low privileges can send a specially crafted IOCTL request to the software's driver component to trigger kernel memory corruption. Successful exploitation can result in the disclosure of sensitive kernel memory information or cause a system crash (BSOD), leading to a denial-of-service condition. The vulnerability is addressed in version v4.7.0.47.
Affected products
- AutomationDirect Productivity Suite <=v4.6.2.2
Timeline
- 2026-07-16: advisory: CISA and NVD published the advisory (ICSA-26-197-04)
- 2026-07-16: patched: AutomationDirect released version v4.7.0.47 to address the issue