Impact
An out‑of‑bounds read has been discovered in the AutomationDirect Productivity Suite, where a locally privileged attacker can inject a crafted IOCTL request to trigger kernel memory corruption. This flaw, identified as CWE‑125, can or causing the application to become unstable or unavailable, thereby compromising confidentiality and availability on the affected system.
Affected Systems
The vulnerability affects AutomationDirect's Productivity Suite prior to version 4.7.0.47. Users running earlier releases of the product should determine whether they are affected, as the flaw exists throughout the earlier firmware that does not include the patch in 4.747 and later. The affected vendor is AutomationDirect, specifically the Productivity Suite component.
Risk and Exploitability
The CVSS scoring reflects a medium severity with a 6.9 score, and the EPSS indicates a very low exploitation likelihood (< 1%). The flaw can only be abused by a local attacker capable of sending IOCTL requests, meaning physical or highly privileged station access is required. While the probability of exploitation is modest, the potential impact—memory disclosure and system instability—demands that the patch be applied promptly. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment