CVE-2026-60140: AutomationDirect Productivity Suite Out-of-bounds Read
An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can lead to exposing sensitive information or causing the affected product to become unstable or unavailable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AutomationDirect Productivity Suiteto a version that resolves this vulnerability.Fixed in v4.7.0.47 and above
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60140?
The severity of CVE-2026-60140 is rated as medium with a score of 6.1.
What impacts can CVE-2026-60140 have on affected systems?
CVE-2026-60140 can lead to kernel memory corruption, potentially exposing sensitive information or causing system instability.
How do I fix CVE-2026-60140?
To fix CVE-2026-60140, update the AutomationDirect Productivity Suite to the latest version that addresses this vulnerability.
Who can exploit CVE-2026-60140?
CVE-2026-60140 can be exploited by a local attacker with access to send crafted IOCTL requests.
What is the nature of the vulnerability in CVE-2026-60140?
CVE-2026-60140 is an out-of-bounds read vulnerability that arises from improper handling of IOCTL requests in the AutomationDirect Productivity Suite.