github.com
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-296-01.json CVE-2025-61934
CRITICAL
AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327
Record summary
CVE-2025-61934 has a selected CVSS score of 9.3 (critical).
Description
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2025 · Source: CVE List
Affected products and versions
8| Product | Source | Version range | Status |
|---|---|---|---|
Productivity 1000 P1-540 CPUBrowse AutomationDirect / Productivity 1000 P1-540 CPUDefault status: unaffected | CVE List | Before SW v4.4.1.19 | affected |
Productivity 1000 P1-550 CPUBrowse AutomationDirect / Productivity 1000 P1-550 CPUDefault status: unaffected | CVE List | Through SW v4.4.1.19 | affected |
Productivity 2000 P2-550 CPUBrowse AutomationDirect / Productivity 2000 P2-550 CPUDefault status: unaffected | CVE List | Through SW v4.4.1.19 | affected |
Productivity 2000 P2-622 CPUBrowse AutomationDirect / Productivity 2000 P2-622 CPUDefault status: unaffected | CVE List | Through SW v4.4.1.19 | affected |
Productivity 3000 P3-530 CPUBrowse AutomationDirect / Productivity 3000 P3-530 CPUDefault status: unaffected | CVE List | Through SW v4.4.1.19 | affected |
Productivity 3000 P3-550E CPUBrowse AutomationDirect / Productivity 3000 P3-550E CPUDefault status: unaffected | CVE List | Through SW V4.2.1.9 | affected |
Productivity 3000 P3-622 CPUBrowse AutomationDirect / Productivity 3000 P3-622 CPUDefault status: unaffected | CVE List | Through SW V4.2.1.9 | affected |
Productivity SuiteBrowse AutomationDirect / Productivity SuiteDefault status: unaffected | CVE List | Through SW V4.2.1.9 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-61934 support.automationdirect.com
https://support.automationdirect.com/docs/securityconsiderations.pdf automationdirect.com
https://www.automationdirect.com/support/software-downloads cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-01