CVE-2025-41770

Summary

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactAXC F 11522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 12522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 2000 EA2019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 21522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 31522019.0.4 < 2026.0.3affected
Phoenix ContactBPC 9102S2019.0.4 < 2026.0.3affected
Phoenix ContactBPC 9202S2019.0.4 < 2026.0.3affected
Phoenix ContactRFC 4072R2019.0.4 < 2026.0.3affected
Phoenix ContactRFC 4072S2019.0.4 < 2026.0.3affected
Phoenix ContactVL3 UPC 2440 EDGE2019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 10002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 20002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 30002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 5002019.0.4 < 2026.0.3affected
Phoenix ContactCatan C12019.0.4 < 2026.0.3affected
Phoenix ContactEPC 15022019.0.4 < 2026.0.3affected
Phoenix ContactEPC 15222019.0.4 < 2026.0.3affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References