CVE-2025-62688

HIGH

Productivity Suite <4.4.1.19 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (8)
AutomationDirect/Productivity 1000 P1-540 CPU < SW v4.4.1.19
AutomationDirect/Productivity 1000 P1-550 CPU < SW v4.4.1.19
AutomationDirect/Productivity 2000 P2-550 CPU < SW v4.4.1.19
AutomationDirect/Productivity 2000 P2-622 CPU < SW v4.4.1.19
AutomationDirect/Productivity 3000 P3-530 CPU < SW v4.4.1.19
AutomationDirect/Productivity 3000 P3-550E CPU < SW V4.2.1.9
AutomationDirect/Productivity 3000 P3-622 CPU < SW V4.2.1.9
AutomationDirect/Productivity Suite < SW V4.2.1.9
Published Oct 23, 2025
Tracked Since Feb 18, 2026