CVE-2025-62688
7.1AutomationDirect · Productivity Suite
An incorrect permission assignment in AutomationDirect Productivity Suite allows low-privileged users to escalate privileges and gain full control over the project.
Executive summary
A critical permission assignment vulnerability in AutomationDirect Productivity Suite allows authenticated low-privileged users to elevate their access to full administrative control.
Vulnerability
The flaw is an incorrect permission assignment (CWE-732) that permits an authenticated user with low-level privileges to modify their assigned role, effectively achieving full project control.
Business impact
Successful exploitation results in full unauthorized control over the industrial control project, posing significant risks to operational integrity and system safety. With a CVSS score of 7.1, this high-severity vulnerability could lead to unauthorized modification of automation logic, potential process disruption, and loss of intellectual property within the industrial environment.
Remediation
Immediate Action: Update the Productivity Suite programming software to version 4.5.0.x or higher and update the firmware of affected Productivity PLCs to the latest available version provided by AutomationDirect.
Proactive Monitoring: Audit system access logs for suspicious account modifications or unexpected changes in user role assignments.
Compensating Controls: Ensure that automation systems are isolated from external networks and strictly enforce access control policies to limit the number of users with low-privileged access to the software.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for complete loss of control over critical industrial infrastructure, administrators must prioritize the update of both the Productivity Suite software and the underlying PLC firmware. Promptly applying these vendor-supplied patches is the only effective way to neutralize the risk of unauthorized privilege escalation and subsequent system compromise.
Sources
Originally found and disclosed by Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect., per the CVE Program record.