CVE 9.3 CRITICAL

AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327_CVE-2025-61934

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Description

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine

AI Analysis

A binding to an unrestricted IP address vulnerability in Productivity Suite allows remote attackers to interact with the ProductivityService PLC simulator and access files and folders on the target machine

Basic Information

ID CVE-2025-61934
Source icscert
Published Oct 23, 2025 at 22:01

Affected Product

Vendor AutomationDirect
Product Productivity Suite
Version v4.4.1.19
Affected Versions AutomationDirect Productivity Suite 0
AutomationDirect Productivity 3000 P3-622 CPU 0
AutomationDirect Productivity 3000 P3-550E CPU 0
AutomationDirect Productivity 3000 P3-530 CPU 0
AutomationDirect Productivity 2000 P2-622 CPU 0
AutomationDirect Productivity 2000 P2-550 CPU 0
AutomationDirect Productivity 1000 P1-550 CPU 0
AutomationDirect Productivity 1000 P1-540 CPU 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity CRITICAL
Vendor AutomationDirect
Product Productivity Suite
Version v4.4.1.19

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.