{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination.","urls":["https://certvde.com"]},{"organization":"Nozomi","summary":"Reporting"}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"Critical"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Multiple vulnerabilities in the PLCnext system allowed low-privileged remote attackers to gain unauthorized access or trigger system reboots by manipulating configuration files and symbolic links. Affected services include watchdog, arp-preinit, and security-profile, potentially exposing critical system files. These issues have been resolved in firmware version 2025.0.2.","title":"Summary"},{"category":"description","text":"Availability, integrity, or confidentiality of the PLCnext Control might be compromised by attacks using these vulnerabilities.","title":"Impact"},{"category":"description","text":"Update to the latest 2025.0.2 Firmware Release. PHOENIX CONTACT recommends to always use an up-to-date version of the PLCnext Engineer.","title":"Remediation"},{"category":"general","text":"Phoenix Contact recommends operating network-capable devices in closed networks or protected with a suitable firewall. For detailed information on our recommendations for measures to protect network-capable devices, please refer to our [application note](https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf).","title":"General Recommendation"}],"publisher":{"category":"vendor","contact_details":"psirt@phoenixcontact.com","name":"Phoenix Contact GmbH & Co. KG","namespace":"https://phoenixcontact.com/psirt"},"references":[{"category":"external","summary":"PCSA-2024-00018","url":"https://phoenixcontact.com/psirt"},{"category":"external","summary":"Phoenix Contact advisory overview at CERT@VDE","url":"https://certvde.com/de/advisories/vendor/phoenixcontact/"},{"category":"external","summary":"Phoenix Contact application note","url":"https://dam-mdc.phoenixcontact.com/asset/156443151564/0a870ae433c19148b80bd760f3a1c1f2/107913_en_03.pdf"},{"category":"self","summary":"VDE-2025-054: Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware - HTML","url":"https://certvde.com/en/advisories/VDE-2025-054"},{"category":"self","summary":"VDE-2025-054: Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware - CSAF","url":"https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-054.json"}],"source_lang":"en","title":"Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware","tracking":{"aliases":["VDE-2025-054","PCSA-2024-00018"],"current_release_date":"2025-07-08T10:00:00.000Z","generator":{"date":"2025-06-25T08:33:16.676Z","engine":{"name":"Secvisogram","version":"2.5.26"}},"id":"VDE-2025-054","initial_release_date":"2025-07-08T10:00:00.000Z","revision_history":[{"date":"2025-07-08T10:00:00.000Z","number":"1","summary":"Initial"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"AXC F 1152","product":{"name":"AXC F 1152","product_id":"CSAFPID-11001","product_identification_helper":{"model_numbers":["1151412"]}}},{"category":"product_name","name":"AXC F 2152","product":{"name":"AXC F 2152","product_id":"CSAFPID-11002","product_identification_helper":{"model_numbers":["2404267"]}}},{"category":"product_name","name":"AXC F 3152","product":{"name":"AXC F 3152","product_id":"CSAFPID-11003","product_identification_helper":{"model_numbers":["1069208"]}}},{"category":"product_name","name":"RFC 4072S","product":{"name":"RFC 4072S","product_id":"CSAFPID-11004","product_identification_helper":{"model_numbers":["1051328"]}}},{"category":"product_name","name":"BPC 9102S","product":{"name":"BPC 9102S","product_id":"CSAFPID-11011","product_identification_helper":{"model_numbers":["1246285"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<2025.0.2","product":{"name":"Firmware <2025.0.2","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"2025.0.2","product":{"name":"Firmware 2025.0.2","product_id":"CSAFPID-22001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Phoenix Contact GmbH & Co. KG"}],"product_groups":[{"group_id":"CSAFGID-61001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"],"summary":"Affected Products."},{"group_id":"CSAFGID-62001","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32004","CSAFPID-32005","CSAFPID-32007"],"summary":"Fixed Product."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <2025.0.2 installed on AXC F 1152","product_id":"CSAFPID-31001","product_identification_helper":{"model_numbers":["1151412"]}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2025.0.2 installed on AXC F 1152","product_id":"CSAFPID-32001","product_identification_helper":{"model_numbers":["1151412"]}},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <2025.0.2 installed on AXC F 2152","product_id":"CSAFPID-31002","product_identification_helper":{"model_numbers":["2404267"]}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 2025.0.2 installed on AXC F 2152","product_id":"CSAFPID-32002","product_identification_helper":{"model_numbers":["2404267"]}},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <2025.0.2 installed on AXC F 3152","product_id":"CSAFPID-31004","product_identification_helper":{"model_numbers":["1069208"]}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware 2025.0.2 installed on AXC F 3152","product_id":"CSAFPID-32004","product_identification_helper":{"model_numbers":["1069208"]}},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware <2025.0.2 installed on RFC 4072S","product_id":"CSAFPID-31005","product_identification_helper":{"model_numbers":["1051328"]}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware 2025.0.2 installed on RFC 4072S","product_id":"CSAFPID-32005","product_identification_helper":{"model_numbers":["1051328"]}},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware <2025.0.2 installed on BPC 9102S","product_id":"CSAFPID-31007","product_identification_helper":{"model_numbers":["1246285"]}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11011"},{"category":"installed_on","full_product_name":{"name":"Firmware 2025.0.2 installed on BPC 9102S","product_id":"CSAFPID-32007","product_identification_helper":{"model_numbers":["1246285"]}},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11011"}]},"vulnerabilities":[{"cve":"CVE-2025-41665","cwe":{"id":"CWE-276","name":"Incorrect Default Permissions"},"notes":[{"category":"description","text":"An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file. ","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32004","CSAFPID-32005","CSAFPID-32007"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]},"remediations":[{"category":"vendor_fix","date":"2025-06-03T10:00:00.000Z","details":"Phoenix Contact strongly recommends to upgrade to firmware 2025.02 which addresses this vulnerability and will be available for download for all affected devices within the next weeks.","group_ids":["CSAFGID-61001"],"product_ids":["CSAFPID-11001","CSAFPID-11002","CSAFPID-11003","CSAFPID-11004","CSAFPID-11011"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":6.5,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":6.5,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]}],"title":"CVE-2025-41665"},{"cve":"CVE-2025-41666","cwe":{"id":"CWE-59","name":"Improper Link Resolution Before File Access ('Link Following')"},"notes":[{"category":"description","text":"A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized.\n","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32004","CSAFPID-32005","CSAFPID-32007"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]},"remediations":[{"category":"vendor_fix","date":"2025-06-03T10:00:00.000Z","details":"Phoenix Contact strongly recommends to upgrade to firmware 2025.02 which addresses this vulnerability and will be available for download for all affected devices within the next weeks.","group_ids":["CSAFGID-61001"],"product_ids":["CSAFPID-11001","CSAFPID-11002","CSAFPID-11003","CSAFPID-11004","CSAFPID-11011"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":8.8,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":8.8,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]}],"title":"CVE-2025-41666"},{"cve":"CVE-2025-41667","cwe":{"id":"CWE-59","name":"Improper Link Resolution Before File Access ('Link Following')"},"notes":[{"category":"description","text":"A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device.\n","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32004","CSAFPID-32005","CSAFPID-32007"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]},"remediations":[{"category":"vendor_fix","date":"2025-06-03T10:00:00.000Z","details":"Phoenix Contact strongly recommends to upgrade to firmware 2025.02 which addresses this vulnerability and will be available for download for all affected devices within the next weeks.","group_ids":["CSAFGID-61001"],"product_ids":["CSAFPID-11001","CSAFPID-11002","CSAFPID-11003","CSAFPID-11004","CSAFPID-11011"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":8.8,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":8.8,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]}],"title":"CVE-2025-41667"},{"cve":"CVE-2025-41668","cwe":{"id":"CWE-59","name":"Improper Link Resolution Before File Access ('Link Following')"},"notes":[{"category":"description","text":"A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file  on the device.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32004","CSAFPID-32005","CSAFPID-32007"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]},"remediations":[{"category":"vendor_fix","date":"2025-06-03T10:00:00.000Z","details":"Phoenix Contact strongly recommends to upgrade to firmware 2025.02 which addresses this vulnerability and will be available for download for all affected devices within the next weeks.","group_ids":["CSAFGID-61001"],"product_ids":["CSAFPID-11001","CSAFPID-11002","CSAFPID-11003","CSAFPID-11004","CSAFPID-11011"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":8.8,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":8.8,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31004","CSAFPID-31005","CSAFPID-31007"]}],"title":"CVE-2025-41668"}]}