Description
An out-of-bounds read vulnerability in the Productivity Suite allows a
local attacker to trigger kernel memory corruption by sending a crafted
IOCTL request. This can lead to exposing sensitive information or
causing the affected product to become unstable or unavailable.
Published: 2026-07-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read has been discovered in the AutomationDirect Productivity Suite, where a locally privileged attacker can inject a crafted IOCTL request to trigger kernel memory corruption. This flaw, identified as CWE‑125, can or causing the application to become unstable or unavailable, thereby compromising confidentiality and availability on the affected system.

Affected Systems

The vulnerability affects AutomationDirect's Productivity Suite prior to version 4.7.0.47. Users running earlier releases of the product should determine whether they are affected, as the flaw exists throughout the earlier firmware that does not include the patch in 4.747 and later. The affected vendor is AutomationDirect, specifically the Productivity Suite component.

Risk and Exploitability

The CVSS scoring reflects a medium severity with a 6.9 score, and the EPSS indicates a very low exploitation likelihood (< 1%). The flaw can only be abused by a local attacker capable of sending IOCTL requests, meaning physical or highly privileged station access is required. While the probability of exploitation is modest, the potential impact—memory disclosure and system instability—demands that the patch be applied promptly. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 01:20 UTC.

Remediation

Vendor Solution

AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above  https://www.automationdirect.com/support/software-downloads


Vendor Workaround

If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed. * Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure. * Use only trusted, dedicated internal networks or air-gapped systems for device communication. * Restrict both physical and logical access to authorized personnel only. * Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software. * Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts. * Enable and regularly review system logs to detect suspicious or unauthorized activity. * Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident. * Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.


OpenCVE Recommended Actions

  • Apply the AutomationDirect Productivity Suite update to version 4.7.0.47 or newer.
  • If an update cannot be performed immediately, isolate the engineering reduce exposure.
  • Configure application whitelisting so that only trusted, pre-approved applications can run, blocking unauthorized software.
  • Deploy antivirus or EDR solutions and configure host-based firewalls to block unauthorized access to authorized personnel only.
  • Enable and regularly review system logs to detect suspicious or unauthorized activity.
  • Maintain secure, tested backups of the PLC and its configurations to minimize downtime.

Generated by OpenCVE AI on July 31, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Automationdirect
Automationdirect productivity Suite
Vendors & Products Automationdirect
Automationdirect productivity Suite

Thu, 16 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can lead to exposing sensitive information or causing the affected product to become unstable or unavailable.
Title AutomationDirect Productivity Suite Out-of-bounds Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Automationdirect Productivity Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-17T13:45:18.561Z

Reserved: 2026-07-09T15:00:24.535Z

Link: CVE-2026-60140

cve-icon Vulnrichment

Updated: 2026-07-17T13:45:13.964Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:30:05Z

Weaknesses