Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-31 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

The engineering laptop was the OT perimeter — AutomationDirect Productivity Suite had nine ways in

Nozomi, 31 October 2025 — unauthenticated file read from the workstation, and a malicious project that fully owns the engineer even when the project is encrypted. Patched in Productivity Suite 4.5.x.x.

RWP Ventures · 2026-09-07 · event 2025-10-31 · 1 min read · priority 8.0

Bottom line up front

CONFIRMED Nozomi Labs, 31 October 2025 — nine vulnerabilities in AutomationDirect Productivity Suite, the Windows engineering environment for Productivity1000/3000 PLCs used in food and beverage, amusement, water/wastewater. Unauthenticated remote attackers can read arbitrary files off the workstation. If an engineer opens a malicious project, the machine is fully compromised — including when the project is encrypted and when the attacker has only low-priv credentials. Nozomi maps loss of productivity (T0828) and theft of cookies/project files as the follow-on. Vendor fixed in 4.5.x.x. This is the workstation, not a PLC RCE. Process impact: ASSESSED if that laptop can download to controllers; not a confirmed plant incident.

Historical backfill of 31 October 2025 reporting; added 7 September 2026.

What happened

Labs treated the engineer's PC as the perimeter and broke the project-file trust model.

Why it mattered

Encryption on the project file was a false floor. The person who opens .download from a vendor email is the control.

Who / what was affected

Sites running Productivity Suite < 4.5.x.x. Water and F&B are in AutomationDirect's installed base, not a victim list.

Technical context

Patch the suite. Do not open project files from unmanaged paths. Isolate EWS from email and browser profiles (the cookie-theft note is the point).

Exploitation / threat status at the time

CONFIRMED nine bugs, vendor patch.

UNKNOWN in-the-wild.

What defenders should have done

  1. 4.5.x.x everywhere Productivity Suite is installed.
  2. EWS gold image without general web/email.
  3. Treat a phished engineer as PLC-equivalent access.

RWP assessment

Confidence: High. Same lesson as PLCnext/CODESYS, earlier in the calendar, different vendor.

Defensive actions

  1. Software bill for every engineering laptop.
  2. Block inbound project files at mail gateway.
  3. Log downloads to Productivity PLCs after a workstation alert.

Sources

  1. Nozomi Networks — Compromising AutomationDirect Productivity Suite
  2. Nozomi Networks Labs — Vulnerability advisories (Productivity Suite CVEs, Oct 2025)
  3. CISA ICS advisories for AutomationDirect Productivity Suite (companion tickets) — CISA ICS advisories for AutomationDirect Productivity Suite (companion tickets)