AutomationDirect Vulnerabilities and Affected Products
Vulnerabilities associated with Productivity 1000 P1-540 CPU.
Products
Clear product- P3-550E15 vulnerabilities
- Productivity Suite15 vulnerabilities
- p3-550e_firmware12 vulnerabilities
- Productivity 1000 P1-540 CPU9 vulnerabilities
- Productivity 1000 P1-550 CPU9 vulnerabilities
- Productivity 2000 P2-550 CPU9 vulnerabilities
- Productivity 2000 P2-622 CPU9 vulnerabilities
- Productivity 3000 P3-530 CPU9 vulnerabilities
- Productivity 3000 P3-550E CPU9 vulnerabilities
- Productivity 3000 P3-622 CPU9 vulnerabilities
- CLICK PLUS C0-0x CPU firmware7 vulnerabilities
- CLICK PLUS C0-1x CPU firmware7 vulnerabilities
- CLICK PLUS C2-x CPU firmware7 vulnerabilities
- C-More EA95 vulnerabilities
- C-MORE EA9 HMI EA9-RHMI4 vulnerabilities
- C-MORE EA9 HMI EA9-T10CL4 vulnerabilities
- C-MORE EA9 HMI EA9-T10WCL4 vulnerabilities
- C-MORE EA9 HMI EA9-T12CL4 vulnerabilities
- C-MORE EA9 HMI EA9-T15CL4 vulnerabilities
- C-MORE EA9 HMI EA9-T15CL-R4 vulnerabilities
- C-MORE EA9 HMI EA9-T6CL4 vulnerabilities
- C-MORE EA9 HMI EA9-T7CL4 vulnerabilities
- C-MORE EA9 HMI EA9-T8CL4 vulnerabilities
- C-MORE EA9 HMI EA0-T7CL-R3 vulnerabilities
- C-MORE EA9 HMI EA9-PGMSW3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-60023MEDIUM | AutomationDirect Productivity Suite Relative Path TraversalA relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine. CWE-23Oct 23, 2025 | CVSS6.3v4.0 | EPSS0.476% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59776MEDIUM | AutomationDirect Productivity Suite Relative Path TraversalA relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and create arbitrary directories on the target machine. CWE-23Oct 23, 2025 | CVSS6.3v4.0 | EPSS0.476% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58429HIGH | AutomationDirect Productivity Suite Relative Path TraversalA relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary files on the target machine. CWE-23Oct 23, 2025 | CVSS8.3v4.0 | EPSS0.574% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58078HIGH | AutomationDirect Productivity Suite Relative Path TraversalA relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and write files with arbitrary data on the target machine. CWE-23Oct 23, 2025 | CVSS8.3v4.0 | EPSS0.574% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58456HIGH | AutomationDirect Productivity Suite Relative Path TraversalA relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine. CWE-23Oct 23, 2025 | CVSS8.2v4.0 | EPSS0.579% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61934CRITICAL | AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine CWE-1327Oct 23, 2025 | CVSS9.3v4.0 | EPSS0.619% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62688MEDIUM | AutomationDirect Productivity Suite Incorrect Permission Assignment for Critical ResourceAn incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project. CWE-732Oct 23, 2025 | CVSS6.9v4.0 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61977HIGH | AutomationDirect Productivity Suite Weak Password Recovery Mechanism for Forgotten PasswordA weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question. CWE-640Oct 23, 2025 | CVSS7.3v4.0 | EPSS0.133% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62498HIGH | AutomationDirect Productivity Suite Relative Path TraversalA relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine where the project is opened. CWE-23Oct 23, 2025 | CVSS8.6v4.0 | EPSS0.517% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |