A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-62498

CVE-2025-62498: Productivity Suite Path Traversal Flaw

CVE-2025-62498 is a ZipSlip path traversal vulnerability in Productivity Suite 4.4.1.19 that enables arbitrary code execution when malicious projects are opened. This article covers technical details, impact, and mitigation.

Published: May 26, 2026

CVE-2025-62498 Overview

CVE-2025-62498 is a relative path traversal vulnerability, commonly known as ZipSlip, affecting AutomationDirect Productivity Suite version 4.4.1.19. The flaw is classified under CWE-23: Relative Path Traversal. An attacker who tampers with a productivity project file can write arbitrary files outside the intended extraction directory. This behavior leads to arbitrary code execution on the engineering workstation that opens the malicious project. CISA published advisory ICSA-25-296-01 documenting the issue within industrial control system environments.

Critical Impact

Opening a tampered Productivity Suite project file allows arbitrary code execution on the engineering workstation, providing a pivot point into operational technology networks.

Affected Products

  • AutomationDirect Productivity Suite version 4.4.1.19
  • Engineering workstations running the vulnerable Productivity Suite installer
  • Industrial control system environments using AutomationDirect productivity projects

Discovery Timeline

  • 2025-10-23 - CVE-2025-62498 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2025-62498

Vulnerability Analysis

The vulnerability stems from improper validation of file paths inside archive entries within Productivity Suite project files. ZipSlip attacks abuse archive formats that allow entries containing relative path sequences such as ../. When the application extracts such an entry without validating the resolved destination path, files can be written to arbitrary locations on the filesystem.

In this case, Productivity Suite extracts contents of project archives without sanitizing entry names. An attacker who modifies a legitimate project can include entries that traverse outside the extraction directory. The application then writes attacker-controlled content to sensitive locations such as Windows startup folders, application directories, or DLL search paths.

The outcome is arbitrary code execution under the privileges of the user opening the project. Engineering workstations often hold credentials and network access to programmable logic controllers (PLCs), making this a viable initial access vector into operational technology environments.

Root Cause

The root cause is missing validation of archive entry paths during project file extraction. The software does not verify that the canonicalized destination path remains within the intended extraction root. This is the defining characteristic of CWE-23 flaws.

Attack Vector

Exploitation requires an attacker to tamper with a Productivity Suite project file and deliver it to a target engineer. Delivery vectors include phishing emails with project attachments, compromised file shares, supply chain modifications to project templates, or removable media. The attack triggers automatically when the engineer opens the modified project in Productivity Suite. No verified public proof-of-concept is currently available for CVE-2025-62498.

Detection Methods for CVE-2025-62498

Indicators of Compromise

  • Unexpected files written outside the standard Productivity Suite project directory after a project is opened
  • New executables, scripts, or shortcuts appearing in user startup folders following Productivity Suite usage
  • Productivity Suite process spawning unexpected child processes such as cmd.exe, powershell.exe, or rundll32.exe
  • Project files received from untrusted sources or with mismatched hashes compared to known-good versions

Detection Strategies

  • Monitor process creation events where the Productivity Suite executable is the parent of scripting interpreters or shell processes
  • Apply behavioral analytics to flag file writes by Productivity Suite to locations outside its working directory, such as %APPDATA%\Microsoft\Windows\Start Menu\Startup
  • Inspect project archive contents before opening to identify entries containing .. or absolute path sequences
  • Correlate engineering workstation file write events with subsequent network connections to PLCs or external hosts

Monitoring Recommendations

  • Enable file integrity monitoring on autostart locations and Productivity Suite installation directories
  • Forward endpoint process and file telemetry from engineering workstations to a centralized security data lake for retention and hunting
  • Audit project file transfers across email gateways, file shares, and removable media on operational technology networks

How to Mitigate CVE-2025-62498

Immediate Actions Required

  • Upgrade Productivity Suite to a fixed version published on the AutomationDirect Software Downloads page
  • Restrict opening of Productivity Suite project files to those received from verified, trusted sources
  • Isolate engineering workstations from general-purpose corporate networks and the internet where feasible
  • Review CISA guidance in ICSA-25-296-01 and apply recommended ICS defensive measures

Patch Information

AutomationDirect provides updated Productivity Suite installers through its software downloads portal. Refer to the CISA ICS Advisory ICSA-25-296-01 and the CSAF document for the exact fixed version and remediation guidance.

Workarounds

  • Validate the integrity of project files using cryptographic hashes before opening them in Productivity Suite
  • Open untrusted project files only inside a non-networked virtual machine snapshot dedicated to triage
  • Apply application allowlisting to prevent unauthorized executables dropped through path traversal from running
  • Limit user privileges on engineering workstations so that arbitrary writes cannot reach system-wide autostart locations

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePath Traversal

  • Vendor/TechProductivity Suite

  • SeverityHIGH

  • CVSS Score8.6

  • EPSS Probability0.07%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-23
  • Technical References
  • GitHub CSAF Document

  • AutomationDirect Software Downloads

  • CISA ICS Advisory ICSA-25-296-01
  • Related CVEs
  • CVE-2025-58078: Productivity Suite Path Traversal Flaw

  • CVE-2025-58429: Productivity Suite Path Traversal Flaw

  • CVE-2025-61934: Productivity Suite RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English