AutomationDirect Productivity Suite
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product. /strong /p p The following versions of AutomationDirect Productivity Suite are affected: /p ul li Productivity Suite lt;=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7 /td td AutomationDirect /td td AutomationDirect Productivity Suite /td td Out-of-bounds Write, Out-of-bounds Read, Divide By Zero /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-60063 /a /h3 div class="csaf-accordion-content" p An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-60063" View CVE Details /a /p hr h4 Affected Products /h4 h5 AutomationDirect Productivity Suite /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br AutomationDirect /div div class="ics-version" strong Product Version: /strong br AutomationDirect Productivity Suite: lt;=v4.6.2.2 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads. br a href="https://www.automationdirect.com/support/software-downloads" https://www.automationdirect.com/support/software-downloads /a /p p strong Mitigation /strong br If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed. /p p strong Mitigation /strong br Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure. /p p strong Mitigation /stron
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.