CVE-2025-61934 Details
Description
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
A vulnerability allowing interaction with the ProductivityService PLC simulator has been identified in AutomationDirect Productivity Suite version 4.4.1.19 and prior. This binding to an unrestricted IP address vulnerability enables an unauthenticated remote attacker to read, write, or delete arbitrary files and folders on the target machine.
Users are advised to update the Productivity Suite software to version 4.5.0.x or higher. For instances where systems cannot be upgraded, AutomationDirect recommends physically disconnecting the PLC from external networks, configuring network segmentation to isolate the PLC, and implementing firewall rules or network access control policies to block traffic to the PLC. Additional guidance can be found in AutomationDirect's security considerations document.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 23, 2025CISA-ADP
Assessed Oct 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1327 | Binding to an Unrestricted IP Address | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AutomationDirect Productivity Suite | <= 4.4.1.19 |
CPE
Remediation
| |
| AutomationDirect Productivity 3000 P3-622 CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Productivity 3000 P3-550E CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Productivity 3000 P3-530 CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Productivity 2000 P2-622 CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Productivity 2000 P2-550 CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Productivity 1000 P1-550 CPU | All versions |
CPE
Remediation
| |
| AutomationDirect Productivity 1000 P1-540 CPU | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | New CVE Received | [email protected] |
Volerion