Description
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine.
Problem types
Product status
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version before SW v4.4.1.19
Credits
Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-296-01
www.automationdirect.com/support/software-downloads
support.automationdirect.com/docs/securityconsiderations.pdf
github.com/...p/csaf_files/OT/white/2025/icsa-25-296-01.json