CVE-2026-60073 Details
Description
An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a system crash or disclosure of kernel memory.
A vulnerability allowing out-of-bounds read has been identified in AutomationDirect Productivity Suite versions through 4.6.2.2. This vulnerability allows a physical attacker to manipulate the length of data sent to a USB device, potentially leading to a system crash or unauthorized disclosure of kernel memory.
Users are advised to update AutomationDirect Productivity Suite to version 4.7.0.47 or later. If the update cannot be applied immediately, it is recommended to disconnect the engineering workstation from external networks, use trusted internal networks for device communication, restrict access to authorized personnel, and configure whitelisting to allow only approved applications to run. Additionally, using antivirus or endpoint detection and response tools, maintaining secure backups of programmable logic controllers and their configurations, and regularly reviewing system logs can help mitigate risks until the update is applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | [email protected] |