AutomationDirect Productivity Suite
- <= v4.6.2.2
A vulnerability allowing out-of-bounds read has been identified in AutomationDirect Productivity Suite versions through 4.6.2.2. This vulnerability allows a physical attacker to manipulate the length of data sent to a USB device, potentially leading to a system crash or unauthorized disclosure of kernel memory.
Exploitation of this vulnerability could cause memory corruption, unauthorized information disclosure, application instability, or a denial-of-service condition on the affected system.
Users are advised to update AutomationDirect Productivity Suite to version 4.7.0.47 or later. If the update cannot be applied immediately, it is recommended to disconnect the engineering workstation from external networks, use trusted internal networks for device communication, restrict access to authorized personnel, and configure whitelisting to allow only approved applications to run. Additionally, using antivirus or endpoint detection and response tools, maintaining secure backups of programmable logic controllers and their configurations, and regularly reviewing system logs can help mitigate risks until the update is applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.