CVE-2025-61977
7.0AutomationDirect · Productivity Suite
A weak password recovery mechanism in AutomationDirect Productivity Suite allows attackers to decrypt project files by answering a single recovery question.
Executive summary
A critical vulnerability in AutomationDirect Productivity Suite software enables unauthorized decryption of project files, posing a significant risk to industrial control system integrity.
Vulnerability
This is a weak password recovery mechanism (CWE-640) that allows an attacker with local access to decrypt an encrypted project file by answering only one recovery question.
Business impact
The ability for an unauthorized party to decrypt project files can lead to the exposure of sensitive intellectual property, logic configurations, and operational parameters. Given the CVSS score of 7.0, this vulnerability presents a high risk to operational continuity and could facilitate further unauthorized modifications to industrial processes. Compromise of these systems may result in significant production downtime or safety hazards within industrial environments.
Remediation
Immediate Action: Update the Productivity Suite programming software to version 4.5.0.x or higher and update the firmware of all affected Productivity PLCs to the latest available version.
Proactive Monitoring: Review system access logs for unauthorized attempts to access or modify project configuration files and monitor for unusual account recovery activities.
Compensating Controls: Ensure that engineering workstations are physically secured and that access to the automation network is strictly limited to authorized personnel using robust network segmentation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk associated with this vulnerability is significant for industrial environments relying on AutomationDirect hardware. Organizations must prioritize the transition to version 4.5.0.x or higher to remediate the weak password recovery logic. Failure to patch these controllers leaves the underlying automation logic vulnerable to exposure and potential manipulation.
Sources
Originally found and disclosed by Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect., per the CVE Program record.