Unauthenticated Denial of Service
Summary
| CVE | CVE-2025-41770 |
|---|---|
| State | PUBLISHED |
| Assigner | CERTVDE |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 08:17:11 UTC |
| Updated | 2026-08-12 08:17:11 UTC |
| Description | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-770 | CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
NoneIntegrity
NoneAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Phoenix Contact | AXC F 1152 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | AXC F 1252 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | AXC F 2000 EA | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | AXC F 2152 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | AXC F 3152 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | BPC 9102S | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | BPC 9202S | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | RFC 4072R | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | RFC 4072S | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | VL3 UPC 2440 EDGE | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | VPLCNEXT CONTROL 1000 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | VPLCNEXT CONTROL 2000 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | VPLCNEXT CONTROL 3000 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | VPLCNEXT CONTROL 500 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | Catan C1 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | EPC 1502 | affected 2019.0.4 2026.0.3 semver | Not specified |
| CNA | Phoenix Contact | EPC 1522 | affected 2019.0.4 2026.0.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json | [email protected] | phoenixcontact.csaf-tp.certvde.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: CyberDanube (en)
There are currently no legacy QID mappings associated with this CVE.