Executive brief
AutomationDirect Productivity Suite, a software package used to program and manage industrial controllers, contains a flaw that can cause the system to crash. A local attacker with access to the workstation can trigger a mathematical error that forces the application to shut down. This results in a denial-of-service condition, potentially disrupting the ability to manage or monitor industrial equipment.
Technical details
A divide-by-zero vulnerability (CWE-369) exists in AutomationDirect Productivity Suite versions 4.6.2.2 and prior. The flaw allows a local attacker with low privileges to trigger a division by zero error, leading to application instability or a complete system crash (denial-of-service). The vulnerability is reachable via local access without requiring user interaction. AutomationDirect has released version 4.7.0.47 to address this issue. Security engineers should also consider restricting physical and logical access to engineering workstations as a mitigating control.
Affected products
- AutomationDirect Productivity Suite <=v4.6.2.2
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
- 2026-07-16: patched: Fixed in version v4.7.0.47