These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A critical stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect Productivity PLCs. The vulnerability, published on 2024-05-23, allows unauthenticated remote attackers to trigger stack-based buffer overflow conditions via specially crafted network packets. This affects multiple Productivity series CPUs across firmware versions [truncated]
A null-byte write vulnerability in the Programming Software Connection FileSystem API of AutomationDirect Productivity PLCs allows remote attackers to cause heap-based memory corruption via specially crafted network packets. The vulnerability affects multiple CPU models across the Productivity 3000, 2000, and 1000 series running specific firmware and software versions. With a CVSS 3.1 score of 8.2 (HIGH), [truncated]
A null-byte write vulnerability in the Programming Software Connection FileSystem API of AutomationDirect Productivity PLCs allows remote attackers to cause heap-based memory corruption via specially crafted network packets. The vulnerability affects multiple Productivity series CPUs across firmware and software versions, with a CVSS 3.1 score of 8.2 (HIGH). The issue was disclosed by CISA on May 23, 2024 [truncated]
A null-byte write vulnerability in the Programming Software Connection FileSystem API of AutomationDirect Productivity PLCs allows remote attackers to cause heap-based memory corruption via specially crafted network packets. The vulnerability affects multiple Productivity series CPUs across firmware and software versions, with a CVSS 3.1 score of 8.2 (HIGH severity). The issue was disclosed by CISA on May [truncated]
A null-byte write vulnerability in the Programming Software Connection FileSystem API of AutomationDirect Productivity PLCs allows remote attackers to cause heap-based memory corruption via specially crafted network packets. The vulnerability affects multiple Productivity series CPUs across firmware and software versions, with a CVSS 3.1 score of 8.2 (HIGH severity). The attack vector is network-based wit [truncated]
A null-byte write vulnerability in the Programming Software Connection FileSystem API of AutomationDirect Productivity PLCs allows remote attackers to cause heap-based memory corruption via specially crafted network packets. The vulnerability affects multiple CPU models across the Productivity 3000, 2000, and 1000 series running specific firmware and software versions. With a CVSS 3.1 score of 8.2 (HIGH), [truncated]
A null-byte write vulnerability in the Programming Software Connection FileSystem API of AutomationDirect Productivity PLCs allows remote attackers to cause heap-based memory corruption via specially crafted network packets. The vulnerability affects multiple CPU models across the Productivity 1000, 2000, and 3000 series running specific firmware and software versions. With a CVSS 3.1 score of 8.2 (High), [truncated]
CVE-2024-24947 is a high-severity buffer overflow vulnerability in AutomationDirect Productivity PLCs, specifically affecting the Programming Software Connection CurrDir functionality in the P3-550E CPU running firmware version 1.2.10.9. Published on May 23, 2024, this vulnerability allows unauthenticated remote attackers to trigger a denial of service condition by sending specially crafted network packet [truncated]
A buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect Productivity PLCs. The flaw allows unauthenticated remote attackers to trigger a denial of service condition by sending specially crafted network packets. The vulnerability affects multiple Productivity series CPUs across firmware versions 1.2.10.9 and 1.2.10.10, as well as Productivity [truncated]
A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect Productivity PLCs. The vulnerability can be triggered by an unauthenticated attacker sending a specially crafted network packet, leading to a buffer overflow condition. This affects multiple Productivity PLC product lines including the P3-550E, P3-550, P3-530, P2-550, P1-550, a [truncated]
A critical code injection vulnerability in AutomationDirect Productivity PLCs allows arbitrary code execution through malicious scan_lib.bin files. The vulnerability affects multiple Productivity series CPUs across firmware and software versions, with a CVSS 3.1 score of 9.8 indicating network-exploitable, unauthenticated remote code execution. The issue was disclosed on May 23, 2024 via CISA ICS advisory [truncated]
A read-what-where vulnerability in AutomationDirect Productivity PLCs allows unauthenticated remote attackers to disclose sensitive information via specially crafted network packets targeting the Programming Software Connection IMM 01A1 Memory Read functionality. The vulnerability affects multiple Productivity series CPUs across firmware and software versions, with a CVSS 3.1 score of 7.5 (HIGH). Publishe [truncated]
A critical write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect Productivity PLCs. The vulnerability allows unauthenticated remote attackers to achieve arbitrary memory writes via specially crafted network packets. This vulnerability affects multiple Productivity series CPUs across the P3-550E, P3-550, P3-530, P2-550, P1-5 [truncated]
A critical vulnerability (CVSS 9.8) in AutomationDirect Productivity PLCs stems from leftover debug code in the Telnet Diagnostic Interface, enabling unauthorized network access via specially crafted requests. Published 2024-05-23, this flaw affects multiple Productivity series CPUs across firmware and software versions. The vendor has released updated software (version 4.2.0.x or higher) and firmware pat [truncated]