← All Advisories

CVE-2025-41770

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-41770

Key Details

CVECVE-2025-41770
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-29
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Phoenix ContactAXC F 1152
Phoenix ContactAXC F 1252
Phoenix ContactAXC F 2000 EA
Phoenix ContactAXC F 2152
Phoenix ContactAXC F 3152
Phoenix ContactBPC 9102S
Phoenix ContactEPC 1522
Phoenix ContactRFC 4072R
Phoenix ContactRFC 4072S
Phoenix ContactVL3 UPC 2440 EDGE
Phoenix ContactVPLCNEXT CONTROL 1000
Phoenix ContactVPLCNEXT CONTROL 2000
Phoenix ContactVPLCNEXT CONTROL 3000
Phoenix ContactVPLCNEXT CONTROL 500
Phoenix ContactBPC 9202S
Phoenix ContactEPC 1502
Phoenix ContactCatan C1
SubsystemsGeneral OT
SectorsMultiple

What to Know

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. (NVD)

What to Do

Monitor Phoenix Contact's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-41770
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-41770