Improper Permissions in Productivity Suite by AutomationDirect
CVE-2025-62688
6.9MEDIUM
What is CVE-2025-62688?
A vulnerability in AutomationDirect's Productivity Suite software enables attackers with low-privilege credentials to alter their user role. This misconfiguration permits them to gain unauthorized full control access to project resources, potentially leading to significant security breaches. It is crucial for users of version 4.4.1.19 to apply necessary patches or updates to mitigate this risk.
Affected Version(s)
Productivity 1000 P1-540 CPU 0
Productivity 1000 P1-550 CPU 0
Productivity 2000 P2-550 CPU 0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
