CISA flags AutomationDirect Productivity Suite kernel flaws
Local-only does not mean low-risk when the target is the engineering workstation that programs manufacturing PLCs.
TL;DR
CISA published ICSA-26-197-04 for six AutomationDirect Productivity Suite vulnerabilities affecting versions through v4.6.2.2 in critical manufacturing deployments worldwide. AutomationDirect recommends updating to v4.7.0.47 or later. The flaws require local or physical access, but they reach kernel-level failure modes: privilege escalation, memory corruption, information disclosure and denial of service.
CISA’s advisory is routine in form and not especially routine in where the risk lands. The affected product is AutomationDirect Productivity Suite through v4.6.2.2, used in critical manufacturing environments worldwide, and the six listed CVEs can be triggered by a local attacker through crafted IOCTL requests or related local access paths. That makes this less a perimeter story than an engineering-workstation story: if the workstation that touches the PLC environment is not controlled, the clean network diagram is doing decorative work.
AutomationDirect’s fix is to move to Productivity Suite v4.7.0.47 or later. Until that update is in place, CISA lists the familiar OT holding pattern: isolate the engineering workstation from external networks, use trusted or air-gapped internal networks for device communication, restrict physical and logical access, allow only approved applications, run antivirus or EDR, review logs and keep tested PLC configuration backups. None of that is novel. It is the compensating-control list you use when patch timing in OT is slower than vulnerability disclosure.
The operational question CISA does not answer is deployment timing. Facilities running affected versions need to verify whether v4.7.0.47 is available in their channel, stage the update against production constraints and treat local access to engineering systems as the control boundary until the patch is installed.
Published ·Deep Fathom