Unrestricted IP Address Vulnerability in Productivity Suite Software by AutomationDirect
CVE-2025-61934

9.3CRITICAL

What is CVE-2025-61934?

An unrestricted IP address vulnerability has been identified in AutomationDirect's Productivity Suite software, specifically in version v4.4.1.19. This flaw allows unauthenticated remote attackers to gain access to the ProductivityService PLC simulator, enabling them to interact with the system in a harmful manner. Attackers could potentially read, write, or delete arbitrary files and folders on the target machine, posing significant risks to data integrity and system security.

Affected Version(s)

Productivity 1000 P1-540 CPU 0

Productivity 1000 P1-550 CPU 0

Productivity 2000 P2-550 CPU 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
.