AutomationDirect Productivity Suite Out-of-Bounds Read Vulnerability Allowing Memory Disclosure and System Crash

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in AutomationDirect Productivity Suite versions through 4.6.2.2. This vulnerability allows a physical attacker to manipulate the length of data sent to a USB device, potentially leading to a system crash or unauthorized disclosure of kernel memory.

Impact

Exploitation of this vulnerability could cause memory corruption, unauthorized information disclosure, application instability, or a denial-of-service condition on the affected system.

Remediation

Users are advised to update AutomationDirect Productivity Suite to version 4.7.0.47 or later. If the update cannot be applied immediately, it is recommended to disconnect the engineering workstation from external networks, use trusted internal networks for device communication, restrict access to authorized personnel, and configure whitelisting to allow only approved applications to run. Additionally, using antivirus or endpoint detection and response tools, maintaining secure backups of programmable logic controllers and their configurations, and regularly reviewing system logs can help mitigate risks until the update is applied.

Added: Jul 16, 2026, 11:05 PM
Updated: Jul 16, 2026, 11:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.