CVE-2025-58078

7.5

AutomationDirect · Productivity Suite

A relative path traversal vulnerability in AutomationDirect Productivity Suite allows unauthenticated remote attackers to write arbitrary files to the target system via the PLC simulator.

Executive summary

A critical relative path traversal vulnerability in AutomationDirect Productivity Suite allows unauthenticated remote attackers to execute arbitrary file writes on the host system.

Vulnerability

This vulnerability is a relative path traversal (CWE-23) flaw within the ProductivityService PLC simulator. It permits an unauthenticated remote attacker to bypass file path restrictions and write files containing arbitrary data to the filesystem of the host machine.

Business impact

The ability for an unauthenticated attacker to write arbitrary files to a system introduces a high risk of system compromise, including the potential for remote code execution or disruption of critical industrial control processes. While the CVSS score of 7.5 indicates a high severity, the impact on industrial integrity and availability makes this a significant operational threat. Unauthorized file modification could lead to extended downtime, loss of control over PLC operations, and potential safety risks within the facility.

Remediation

Immediate Action: Update the Productivity Suite programming software to version 4.5.0.x or higher and update the firmware on all affected Productivity PLC units to the latest available versions.

Proactive Monitoring: Monitor network traffic for unusual connections directed at the PLC simulator service and review system logs for unauthorized file write events or unexpected modifications to configuration files.

Compensating Controls: Ensure that industrial control systems are isolated from external networks using robust firewalls and access control lists to prevent unauthorized remote access to the PLC simulator.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary file writes on critical industrial hardware, organizations must prioritize patching these systems. Security teams should verify their current versions against the affected list immediately and schedule maintenance windows to apply the necessary software and firmware updates provided by AutomationDirect. Failure to remediate this vulnerability increases the risk of unauthorized system manipulation and operational failure.

Sources

Originally found and disclosed by Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect., per the CVE Program record.