CVE-2025-58429

7.5

AutomationDirect · Productivity Suite and Productivity PLC CPUs

A relative path traversal vulnerability in AutomationDirect Productivity Suite allows unauthenticated remote attackers to delete arbitrary files via the PLC simulator.

Executive summary

An unauthenticated remote code execution style vulnerability in AutomationDirect Productivity Suite allows attackers to delete arbitrary files on the target system.

Vulnerability

This is a relative path traversal vulnerability (CWE-23) affecting the ProductivityService PLC simulator. It permits an unauthenticated remote attacker to perform unauthorized file deletions on the host machine.

Business impact

The ability for an unauthenticated attacker to delete arbitrary files on a system hosting industrial control software presents a high risk to operational integrity. A successful exploit could lead to significant system downtime, loss of configuration data, or the disruption of critical automation processes. Given the CVSS score of 7.5, this vulnerability is classified as High severity and requires immediate prioritization in industrial environments.

Remediation

Immediate Action: Update the Productivity Suite programming software to version 4.5.0.x or higher and update the firmware of all affected Productivity PLCs to the latest available version.

Proactive Monitoring: Review system access logs for unauthorized file modification attempts and monitor network traffic directed toward the ProductivityService PLC simulator for anomalous patterns.

Compensating Controls: Ensure that industrial control systems are isolated from external networks and utilize strict firewall policies to limit access to the PLC simulator service to only authorized workstations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability poses a significant risk to industrial operations due to the potential for destructive file deletion. Organizations running affected AutomationDirect hardware or software must prioritize upgrading to the latest versions provided by the vendor. Failure to apply these updates leaves critical control infrastructure susceptible to remote disruption.

Sources

Originally found and disclosed by Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect., per the CVE Program record.