CVE-2026-60073: AutomationDirect Productivity Suite Out-of-bounds Read
An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a system crash or disclosure of kernel memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AutomationDirect Productivity Suiteto a version that resolves this vulnerability.Fixed in v4.7.0.47
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60073?
The severity of CVE-2026-60073 is rated as medium with a CVSS score of 5.9.
What types of attacks are possible with CVE-2026-60073?
CVE-2026-60073 allows a physical attacker to exploit an out-of-bounds read, potentially leading to a system crash or disclosure of kernel memory.
How can I mitigate the risks associated with CVE-2026-60073?
Mitigation strategies for CVE-2026-60073 include restricting physical access to the affected systems and implementing security measures for USB device interactions.
What software is affected by CVE-2026-60073?
CVE-2026-60073 affects the AutomationDirect Productivity Suite software.
What are the implications of CVE-2026-60073 for users?
Users of the AutomationDirect Productivity Suite should be aware that CVE-2026-60073 can lead to disruptions or exposure of sensitive information.