A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and write files with arbitrary data on the target machine.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-01
https://www.automationdirect.com/support/software-downloads
https://support.automationdirect.com/docs/securityconsiderations.pdf
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-296-01.json
Published: 2025-10-23
Updated: 2025-10-23
Base Score: 6.1
Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:C
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H
Severity: High
Base Score: 8.3
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:L
Severity: High
EPSS: 0.00177