CVE-2025-58456 - CVE House
Back to Database
Status published High CVE-2025-58456

AutomationDirect Productivity Suite Relative Path Traversal

Vulnerability Description

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58456

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Luca Borzacchiello of Nozomi Networks reported these vulnerabilities to AutomationDirect.

Affected Vendor

AutomationDirect

View all reports →

Affected Software

Productivity Suite, Productivity 3000 P3-622 CPU, Productivity 3000 P3-550E CPU, Productivity 3000 P3-530 CPU, Productivity 2000 P2-622 CPU, Productivity 2000 P2-550 CPU, Productivity 1000 P1-550 CPU, Productivity 1000 P1-540 CPU
Vulnerable Versions:
0

Timeline

Official Publish: October 23rd, 2025
Last Modified: October 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses (CWE)