CVE-2025-61977: AutomationDirect Productivity Suite Weak Password Recovery Mechanism for Forgotten Password
A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61977?
CVE-2025-61977 has been classified as a medium severity vulnerability due to the potential for unauthorized access through weak password recovery.
How do I fix CVE-2025-61977?
To fix CVE-2025-61977, upgrade the affected Productivity Suite software to the latest version provided by AutomationDirect.
What are the affected versions in CVE-2025-61977?
CVE-2025-61977 affects AutomationDirect Productivity Suite version v4.4.1.19 and prior, as well as various Productivity 3000 and 2000 CPU models running the same software version.
Can CVE-2025-61977 lead to data breaches?
Yes, CVE-2025-61977 can allow attackers to decrypt sensitive project files, potentially leading to significant data breaches.
What should I do if I am using an affected product for CVE-2025-61977?
If using an affected product for CVE-2025-61977, immediately upgrade to the patched version to mitigate the vulnerability.