CVE-2025-61977: AutomationDirect Productivity Suite Weak Password Recovery Mechanism for Forgotten Password

Published Oct 23, 2025
·
Updated

A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.

Affected Software

8 affected components
: AutomationDirect Productivity Suite: v4.4.1.19 and prior
: AutomationDirect Productivity 3000 P3-622 CPU: SW v4.4.1.19 and prior
: AutomationDirect Productivity 3000 P3-550E CPU: SW v4.4.1.19 and prior
: AutomationDirect Productivity 3000 P3-530 CPU: SW v4.4.1.19 and prior
: AutomationDirect Productivity 2000 P2-622 CPU: SW v4.4.1.19 and prior
: AutomationDirect Productivity 2000 P2-550 CPU: SW v4.4.1.19 and prior
: AutomationDirect Productivity 1000 P1-550 CPU: SW v4.4.1.19 and prior
: AutomationDirect Productivity 1000 P1-540 CPU: SW v4.4.1.19 and prior

Remediation

Information

AutomationDirect recommends that users do the following: * Update the Productivity Suite programming software to version 4.5.0.x or higher. * Update the firmware of Productivity PLCs to the latest version. https://www.automationdirect.com/support/software-downloads * Although automation networks and systems come equipped with built-in password protection mechanisms, this represents a fraction of the security measures needed to safeguard these systems. * It is imperative that automation control system networks integrate data protection and security measures that match, if not exceed, the robustness of conventional business computer systems. * AutomationDirect advises users of PLCs, HMI products, and SCADA systems to conduct a thorough network security analysis to ascertain the appropriate level of security necessary for their specific application.

Event History

Oct 23, 2025
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via ICS·09:53 PM
SeverityWeaknessAffected Software
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Jan 21, 57782
Event
via NVD·01:42 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-61977?

CVE-2025-61977 has been classified as a medium severity vulnerability due to the potential for unauthorized access through weak password recovery.

2

How do I fix CVE-2025-61977?

To fix CVE-2025-61977, upgrade the affected Productivity Suite software to the latest version provided by AutomationDirect.

3

What are the affected versions in CVE-2025-61977?

CVE-2025-61977 affects AutomationDirect Productivity Suite version v4.4.1.19 and prior, as well as various Productivity 3000 and 2000 CPU models running the same software version.

4

Can CVE-2025-61977 lead to data breaches?

Yes, CVE-2025-61977 can allow attackers to decrypt sensitive project files, potentially leading to significant data breaches.

5

What should I do if I am using an affected product for CVE-2025-61977?

If using an affected product for CVE-2025-61977, immediately upgrade to the patched version to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203