Phoenix Contact Rfc 4072S vulnerabilities
8 known vulnerabilities affecting phoenix_contact/rfc_4072s.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-41670HIGHCVSS 8.7≥ 0.0.0, < 2026.0.32026-05-27
CVE-2025-41670 [HIGH] CWE-427 CVE-2025-41670: A local user with low privileges may be able to influence the behavior of a privileged system servic
A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the se
nvd
CVE-2025-41669HIGHCVSS 8.7≥ 0.0.0, < 2026.0.32026-05-27
CVE-2025-41669 [HIGH] CWE-347 CVE-2025-41669: The Web-based Management allows a remote low privileged Engineer user to install additional APPs on
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allo
nvd
CVE-2025-41666HIGHCVSS 8.8fixed in 2025.0.22025-07-08
CVE-2025-41666 [HIGH] CWE-59 CVE-2025-41666: A low privileged remote attacker with file access can replace a critical file used by the watchdog t
A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized.
nvd
CVE-2025-41668HIGHCVSS 8.8fixed in 2025.0.22025-07-08
CVE-2025-41668 [HIGH] CWE-59 CVE-2025-41668: A low privileged remote attacker with file access can replace a critical file or folder used by the
A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device.
nvd
CVE-2025-41667HIGHCVSS 8.8fixed in 2025.0.22025-07-08
CVE-2025-41667 [HIGH] CWE-59 CVE-2025-41667: A low privileged remote attacker with file access can replace a critical file used by the arp-preini
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device.
nvd
CVE-2025-41665MEDIUMCVSS 6.5fixed in 2025.0.22025-07-08
CVE-2025-41665 [MEDIUM] CWE-276 CVE-2025-41665: An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.
nvd
CVE-2023-46142HIGHCVSS 8.8≤ 2024.02023-12-14
CVE-2023-46142 [HIGH] CWE-732 CVE-2023-46142: A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
nvd
CVE-2023-46144MEDIUMCVSS 6.5≤ 2024.02023-12-14
CVE-2023-46144 [MEDIUM] CWE-494 CVE-2023-46144: A download of code without integrity check vulnerability in PLCnext products allows an remote attack
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
nvd