Impact
An out‑of‑bounds read in AutomationDirect Productivity Suite allows a nearby attacker to dictate the length of data sent to a USB device. By manipulating this length the attacker can trigger a system crash or read unintended kernel memory, potentially compromising both availability and confidentiality.
Affected Systems
Vulnerable systems run AutomationDirect Productivity Suite; no specific version list is provided in the data, so any installation that has not been upgraded to v4.7.0.47 or later should be considered at risk.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation. The issue is not listed in the CISA KEV catalog. The attack vector appears to be physical, requiring proximity to the affected workstation or device. If exploited, the flaw could lead to denial of service or the disclosure of kernel memory. The vendor recommends updating to v4.7.0.47 or later to eliminate the flaw.
OpenCVE Enrichment