CVE-2025-58429
7.5AutomationDirect · Productivity Suite and Productivity PLC CPUs
A relative path traversal vulnerability in AutomationDirect Productivity Suite allows unauthenticated remote attackers to delete arbitrary files via the PLC simulator.
Executive summary
An unauthenticated remote code execution style vulnerability in AutomationDirect Productivity Suite allows attackers to delete arbitrary files on the target system.
Vulnerability
This is a relative path traversal vulnerability (CWE-23) affecting the ProductivityService PLC simulator. It permits an unauthenticated remote attacker to perform unauthorized file deletions on the host machine.
Business impact
The ability for an unauthenticated attacker to delete arbitrary files on a system hosting industrial control software presents a high risk to operational integrity. A successful exploit could lead to significant system downtime, loss of configuration data, or the disruption of critical automation processes. Given the CVSS score of 7.5, this vulnerability is classified as High severity and requires immediate prioritization in industrial environments.
Remediation
Immediate Action: Update the Productivity Suite programming software to version 4.5.0.x or higher and update the firmware of all affected Productivity PLCs to the latest available version.
Proactive Monitoring: Review system access logs for unauthorized file modification attempts and monitor network traffic directed toward the ProductivityService PLC simulator for anomalous patterns.
Compensating Controls: Ensure that industrial control systems are isolated from external networks and utilize strict firewall policies to limit access to the PLC simulator service to only authorized workstations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability poses a significant risk to industrial operations due to the potential for destructive file deletion. Organizations running affected AutomationDirect hardware or software must prioritize upgrading to the latest versions provided by the vendor. Failure to apply these updates leaves critical control infrastructure susceptible to remote disruption.
Sources
Originally found and disclosed by Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect., per the CVE Program record.