Description
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
Problem types
Product status
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version before SW v4.4.1.19
Credits
Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-296-01
www.automationdirect.com/support/software-downloads
support.automationdirect.com/docs/securityconsiderations.pdf
github.com/...p/csaf_files/OT/white/2025/icsa-25-296-01.json