CVE-2025-58456: AutomationDirect Productivity Suite Relative Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version
4.4.1.19.
The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58456?
CVE-2025-58456 is classified as a high severity vulnerability due to its potential to allow unauthorized remote file access.
How do I fix CVE-2025-58456?
To fix CVE-2025-58456, upgrade the affected Productivity Suite software to the latest version beyond 4.4.1.19.
What products are affected by CVE-2025-58456?
CVE-2025-58456 affects multiple versions of AutomationDirect Productivity Suite and its associated CPU models listed in the vulnerability description.
What type of attack is possible with CVE-2025-58456?
CVE-2025-58456 allows an unauthenticated remote attacker to perform a relative path traversal to read arbitrary files on the targeted system.
Is CVE-2025-58456 easy to exploit?
Yes, due to its unauthenticated nature, CVE-2025-58456 can be easily exploited by attackers with network access to the vulnerable systems.