Machine-generated analysis · WAYSCloud LLM
AutomationDirect Productivity Suite versions up to 4.6.2.2 are listed as affected.
Context
The advisory concerns AutomationDirect Productivity Suite, a software product from AutomationDirect. It states that several vulnerabilities (out-of-bounds write, out-of-bounds read, divide-by-zero) could allow a local or physically proximate attacker to cause memory corruption, information disclosure, instability, or denial-of-service. The product is deployed worldwide in the critical manufacturing sector. Mitigation guidance recommends upgrading to version 4.7.0.47 or later.
Operator considerations
Check: Verify the installed Productivity Suite version is not older than v4.7.0.47.
Isolate: Disconnect engineering workstations from external networks and use only trusted internal or air-gapped networks.
Patch: Update the suite to version 4.7.0.47 or newer from AutomationDirect’s support site.
Log: Monitor for unusual IOCTL requests or kernel memory errors on affected systems.
Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product.
The following versions of AutomationDirect Productivity Suite are affected:
Productivity Suite
Read the full advisory on CISA →