Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-31 and was added to the RWP archive on 2026-09-07.
The engineering laptop was the OT perimeter — AutomationDirect Productivity Suite had nine ways in
Nozomi, 31 October 2025 — unauthenticated file read from the workstation, and a malicious project that fully owns the engineer even when the project is encrypted. Patched in Productivity Suite 4.5.x.x.
Bottom line up front
CONFIRMED Nozomi Labs, 31 October 2025 — nine vulnerabilities in AutomationDirect Productivity Suite, the Windows engineering environment for Productivity1000/3000 PLCs used in food and beverage, amusement, water/wastewater. Unauthenticated remote attackers can read arbitrary files off the workstation. If an engineer opens a malicious project, the machine is fully compromised — including when the project is encrypted and when the attacker has only low-priv credentials. Nozomi maps loss of productivity (T0828) and theft of cookies/project files as the follow-on. Vendor fixed in 4.5.x.x. This is the workstation, not a PLC RCE. Process impact: ASSESSED if that laptop can download to controllers; not a confirmed plant incident.
Historical backfill of 31 October 2025 reporting; added 7 September 2026.
What happened
Labs treated the engineer's PC as the perimeter and broke the project-file trust model.
Why it mattered
Encryption on the project file was a false floor. The person who opens .download from a vendor email is the control.
Who / what was affected
Sites running Productivity Suite < 4.5.x.x. Water and F&B are in AutomationDirect's installed base, not a victim list.
Technical context
Patch the suite. Do not open project files from unmanaged paths. Isolate EWS from email and browser profiles (the cookie-theft note is the point).
Exploitation / threat status at the time
CONFIRMED nine bugs, vendor patch.
UNKNOWN in-the-wild.
What defenders should have done
- 4.5.x.x everywhere Productivity Suite is installed.
- EWS gold image without general web/email.
- Treat a phished engineer as PLC-equivalent access.
RWP assessment
Confidence: High. Same lesson as PLCnext/CODESYS, earlier in the calendar, different vendor.
Defensive actions
- Software bill for every engineering laptop.
- Block inbound project files at mail gateway.
- Log downloads to Productivity PLCs after a workstation alert.
Sources
- Nozomi Networks — Compromising AutomationDirect Productivity Suite
- Nozomi Networks Labs — Vulnerability advisories (Productivity Suite CVEs, Oct 2025)
- CISA ICS advisories for AutomationDirect Productivity Suite (companion tickets) — CISA ICS advisories for AutomationDirect Productivity Suite (companion tickets)