Phoenix Contact Rfc 4072R vulnerabilities
4 known vulnerabilities affecting phoenix_contact/rfc_4072r.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-41670HIGHCVSS 8.7≥ 0.0.0, < 2026.0.32026-05-27
CVE-2025-41670 [HIGH] CWE-427 CVE-2025-41670: A local user with low privileges may be able to influence the behavior of a privileged system servic
A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the se
nvd
CVE-2025-41669HIGHCVSS 8.7≥ 0.0.0, < 2026.0.32026-05-27
CVE-2025-41669 [HIGH] CWE-347 CVE-2025-41669: The Web-based Management allows a remote low privileged Engineer user to install additional APPs on
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allo
nvd
CVE-2023-46142HIGHCVSS 8.8≤ 2024.02023-12-14
CVE-2023-46142 [HIGH] CWE-732 CVE-2023-46142: A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
nvd
CVE-2023-46144MEDIUMCVSS 6.5≤ 2024.02023-12-14
CVE-2023-46144 [MEDIUM] CWE-494 CVE-2023-46144: A download of code without integrity check vulnerability in PLCnext products allows an remote attack
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
nvd