Improper Permissions in Productivity Suite by AutomationDirect
CVE-2025-62688

6.9MEDIUM

What is CVE-2025-62688?

A vulnerability in AutomationDirect's Productivity Suite software enables attackers with low-privilege credentials to alter their user role. This misconfiguration permits them to gain unauthorized full control access to project resources, potentially leading to significant security breaches. It is crucial for users of version 4.4.1.19 to apply necessary patches or updates to mitigate this risk.

Affected Version(s)

Productivity 1000 P1-540 CPU 0

Productivity 1000 P1-550 CPU 0

Productivity 2000 P2-550 CPU 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
.