VORANT. Threat Intelligence Sign in Get the full feed

AutomationDirect Productivity Suite has six flaws

medium vulnerability manufacturing

CISA disclosed six local-access vulnerabilities in AutomationDirect Productivity Suite that can crash systems or leak kernel memory; patch to v4.7.0.47 is available.

CISA published an ICS advisory covering six vulnerabilities in AutomationDirect Productivity Suite version 4.6.2.2 and earlier, an engineering workstation software used to program AutomationDirect PLCs in critical manufacturing environments worldwide. The flaws include multiple out-of-bounds write and read issues triggered via crafted IOCTL requests that can cause kernel memory corruption, information disclosure, or denial of service, as well as a divide-by-zero bug and a USB-related out-of-bounds read that a physical attacker could exploit to crash the system or expose kernel memory.

All six issues require local or physical access to the engineering workstation and are not remotely exploitable, limiting the practical attack surface to insiders or attackers who have already gained a foothold or physical proximity. CISA states no public exploitation has been reported. AutomationDirect has released version 4.7.0.47 to remediate the vulnerabilities, and CISA recommends standard ICS network isolation, access restriction, and application whitelisting as compensating controls where patching cannot occur immediately. The vulnerabilities were responsibly disclosed by Luca Borzacchiello of Nozomi Networks.

Mentioned in this report

Vulnerabilities CVE-2026-57896CVE-2026-60063CVE-2026-60073CVE-2026-60140CVE-2026-61378CVE-2026-61389

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free