Description
An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.
Problem types
Product status
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version before SW v4.4.1.19
Credits
Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-296-01
www.automationdirect.com/support/software-downloads
support.automationdirect.com/docs/securityconsiderations.pdf
github.com/...p/csaf_files/OT/white/2025/icsa-25-296-01.json