Impact
An out-of-bounds write flaw in the AutomationDirect Productivity Suite allows a local attacker to send a crafted IOCTL request that corrupts kernel memory. The memory corruption can enable an attacker to elevate privileges on the affected system, potentially compromising the integrity of the device and its control functions. The weakness is categorized as a buffer overflow (CWE-787).
Affected Systems
The affected product is AutomationDirect:Productivity Suite, used in industrial control environments. Versions prior to v4.7.0.47 are vulnerable; the vendor recommends upgrading to v4.7.0.47 or later.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, but the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires local access to a machine running the affected software, such as a PLC engineering workstation, and the ability to issue a malicious IOCTL command. The vulnerability enables privilege escalation by an attacker who has local access.
OpenCVE Enrichment