AutomationDirect Productivity Suite
- <= v4.6.2.2
A vulnerability allowing out-of-bounds read has been identified in AutomationDirect Productivity Suite versions through 4.6.2.2. This vulnerability allows a local attacker to send a crafted IOCTL request that triggers kernel memory corruption, potentially leading to limited information disclosure or disruption of the affected application.
Exploitation of this vulnerability could cause memory corruption, unauthorized information disclosure, application instability, or a denial-of-service condition in the affected product.
Users are advised to update AutomationDirect Productivity Suite to version 4.7.0.47 or above. If the update cannot be applied immediately, it is recommended to disconnect the engineering workstation from external networks, use trusted internal networks for device communication, restrict access to authorized personnel, configure application whitelisting, use antivirus or EDR tools, enable and review system logs, maintain secure backups of PLC configurations, and evaluate risks of running outdated firmware.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.