AutomationDirect Productivity Suite

MonitorCVSS 7ICS-CERT ICSA-26-197-04Jul 16, 2026
AutomationDirect
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

AutomationDirect Productivity Suite versions 4.6.2.2 and earlier contain memory corruption vulnerabilities (CWE-787, CWE-125, CWE-369) that could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or denial-of-service in the affected product.

What this means
What could happen
An attacker with local or physical access to an engineering workstation running Productivity Suite could corrupt memory or crash the application, potentially causing unintended changes to device configurations or loss of engineering access during critical operations.
Who's at risk
Engineering and automation staff who use AutomationDirect Productivity Suite to configure and maintain automation devices (PLCs, drives, I/O modules) in water treatment, electric distribution, HVAC, and other critical infrastructure environments.
How it could be exploited
An attacker with local access to the engineering workstation could exploit memory corruption vulnerabilities (CWE-787, CWE-125, CWE-369) to execute arbitrary code, corrupt process memory, or trigger a denial-of-service condition that crashes the Productivity Suite application.
Prerequisites
  • Local or physical access to the engineering workstation running Productivity Suite
  • User account with permissions to run the Productivity Suite application
  • Ability to interact with the workstation or supply specially crafted input to the application
Local/physical access requiredAffects engineering workstationsNo authentication bypassMemory corruption vulnerabilities
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
Productivity Suite≤ v4.6.2.2No fix yet
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDDisconnect engineering workstations from external networks (internet, corporate LAN) until patching can be completed
HARDENINGRestrict physical and logical access to engineering workstations to authorized personnel only
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Productivity Suite to version 4.7.0.47 or later
Long-term hardening
0/1
HARDENINGUse dedicated, air-gapped internal networks for device communication and engineering workstation access
API: /api/v1/advisories/014c8ab9-b14e-47c8-9485-11cb5f14ab8b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

AutomationDirect Productivity Suite | CVSS 7 - OTPulse