CVE-2025-62498

8.8

AutomationDirect · Productivity Suite

A relative path traversal vulnerability (ZipSlip) in AutomationDirect Productivity Suite allows an attacker to execute arbitrary code by tampering with a productivity project file.

Executive summary

A critical path traversal vulnerability in AutomationDirect Productivity Suite allows an attacker with high privileges to achieve arbitrary code execution on the host machine.

Vulnerability

This is a relative path traversal flaw, identified as CWE-23 (ZipSlip), which occurs when the software fails to properly sanitize project file paths. The vulnerability requires an attacker to possess high privileges to interact with and tamper with the project file.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its high impact on system integrity and availability. Successful exploitation allows for arbitrary code execution, which could lead to full control over the industrial control system, potential physical process disruption, or unauthorized access to sensitive project data.

Remediation

Immediate Action: Update the Productivity Suite programming software to version 4.5.0.x or higher and update the firmware of affected Productivity PLCs to the latest available version provided by AutomationDirect.

Proactive Monitoring: Monitor the environment for unauthorized modifications to project files and review audit logs for anomalous activity within the engineering workstation environment.

Compensating Controls: Ensure that engineering workstations are isolated from untrusted networks and enforce strict access controls on project file directories to prevent unauthorized tampering.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of the potential impact on industrial control systems, organizations using the affected AutomationDirect software must prioritize the application of the vendor-supplied updates. Failure to patch these systems could expose critical infrastructure to remote code execution risks, necessitating immediate attention from OT and IT security teams.

Sources

Originally found and disclosed by Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect., per the CVE Program record.