Description
A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.
Problem types
Product status
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version before SW v4.4.1.19
Credits
Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-296-01
github.com/...p/csaf_files/OT/white/2025/icsa-25-296-01.json
www.automationdirect.com/support/software-downloads
support.automationdirect.com/docs/securityconsiderations.pdf