A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-01
https://www.automationdirect.com/support/software-downloads
https://support.automationdirect.com/docs/securityconsiderations.pdf
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-296-01.json
Published: 2025-10-23
Updated: 2025-10-23
Base Score: 5.4
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N
Severity: Medium
Base Score: 6.8
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Severity: Medium
Base Score: 8.2
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Severity: High
EPSS: 0.00065