A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
The ProductivityService of the PLC simulator listens on an unrestricted IP address (e.g., 0.0.0.0), meaning it is available on all network interfaces of the machine, including potentially from external networks. The lack of authentication mechanisms or access restrictions means that any remote attacker with network access to the service port can communicate with it directly. The attacker can then use this communication to read, modify, or delete any files and folders in the target machine's file system.
An unauthenticated remote attacker can read, write, or delete any files and folders on the target machine, which may lead to data theft, sabotage of industrial system configurations (OT/ICS), or complete data destruction on the host.
Patches available from the manufacturer should be applied according to the references. Software update is available at: https://www.automationdirect.com/support/software-downloads. Additionally, it is recommended to review the manufacturer's security document: https://support.automationdirect.com/docs/securityconsiderations.pdf. Until the patch is deployed, it is recommended to isolate machines with the installed software using a firewall and restrict network access to ProductivityService ports only to trusted hosts.
AutomationDirect Productivity Suite version v4.4.1.19
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X