CVE-2025-41665

Severity
6.5MEDIUM
EPSS
0.2%
top 62.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8

Description

An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5phoenix_contact/bpc_9102s< 2025.0.2
CVEListV5phoenix_contact/rfc_4072s< 2025.0.2
CVEListV5phoenix_contact/axc_f_1152< 2025.0.2
CVEListV5phoenix_contact/axc_f_2152< 2025.0.2
CVEListV5phoenix_contact/axc_f_3152< 2025.0.2

🔴Vulnerability Details

2
GHSA
GHSA-x2c5-vc55-gpgh: An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config2025-07-08
CVEList
Phoenix Contact: DoS of the PLC due to incorrect default permissions possible2025-07-08
CVE-2025-41665 (MEDIUM CVSS 6.5) | An low privileged remote attacker c | cvebase.io