CVE-2025-62688
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-23
Last updated on: 2025-10-27
Assigner: ICS-CERT
Description
Description
An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| automationdirect | productivity_3000 | p3-550e |
| automationdirect | productivity_suite | 4.5.0 |
| automationdirect | productivity_3000 | p3-622 |
| automationdirect | productivity_1000 | p1-550 |
| automationdirect | productivity_1000 | p1-540 |
| automationdirect | productivity_2000 | p2-622 |
| automationdirect | productivity_3000 | p3-530 |
| automationdirect | productivity_2000 | p2-550 |
| automationdirect | productivity_suite | 4.4.1.19 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |