CVE-2025-41693

Severity
4.3MEDIUM
EPSS
0.4%
top 39.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages138 packages

CVEListV5phoenix_contact/fl_nat_20080.0.03.50
CVEListV5phoenix_contact/fl_nat_22080.0.03.50
CVEListV5phoenix_contact/fl_switch_20050.0.03.50
CVEListV5phoenix_contact/fl_switch_20080.0.03.50
CVEListV5phoenix_contact/fl_switch_20160.0.03.50

🔴Vulnerability Details

2
CVEList
Authenticated Denial-of-Service via SSH2025-12-09
GHSA
GHSA-q7f9-7f36-x3ch: A low privileged remote attacker can use the ssh feature to execute commands directly after login2025-12-09
CVE-2025-41693 (MEDIUM CVSS 4.3) | A low privileged remote attacker ca | cvebase.io