9.8
CVE-2025-41769
- EPSS 0.59%
- Veröffentlicht 12.08.2026 08:05:54
- Zuletzt bearbeitet 13.08.2026 16:17:50
- CVE-Watchlists
- Unerledigt
Unauthenticated Buffer Overflow in PROFINET Service
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPhoenix Contact
≫
Produkt
AXC F 1152
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
AXC F 1252
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
AXC F 2152
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
AXC F 3152
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
BPC 9102S
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
BPC 9202S
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
RFC 4072R
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
RFC 4072S
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
VL3 UPC 2440 EDGE
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
VPLCNEXT CONTROL 1000
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
VPLCNEXT CONTROL 2000
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
VPLCNEXT CONTROL 3000
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
VPLCNEXT CONTROL 500
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
EPC 1502
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
HerstellerPhoenix Contact
≫
Produkt
EPC 1522
Default Statusunaffected
Version
2019.0.4
Version <
2026.0.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.45 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| info@cert.vde.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json