Weak Password Recovery in Productivity Suite Software by Automation Direct
CVE-2025-61977

7.3HIGH

What is CVE-2025-61977?

A vulnerability in the Productivity Suite software allows unauthorized access through a weak password recovery mechanism. Attackers can decrypt sensitive project data by correctly answering only one recovery question. This security flaw emphasizes the need for robust password management practices to protect critical assets and maintain data integrity.

Affected Version(s)

Productivity 1000 P1-540 CPU 0

Productivity 1000 P1-550 CPU 0

Productivity 2000 P2-550 CPU 0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
.