Sceawere

Vulnerability Detail

CVE-2025-41770UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PLCnext Engineer Unauthenticated Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
Phoenix Contact
Product
AXC F 1152
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-12T08:17:11.910Z",
  "pubdate": "2026-08-12T08:17:11.910Z",
  "executiveSummary": "An unauthenticated denial-of-service vulnerability has been identified within the communication interface of PLCnext Engineer. This security flaw enables a remote, unauthenticated attacker to disrupt access to the device via the client application, effectively cutting off remote management and engineering interactions.\nSuccessful exploitation of this vulnerability halts critical communication channels, leaving the target system unresponsive to client connection attempts until an administrative user manually restarts the affected PLCnext service. The risk implications are severe for industrial control environments where operational visibility and rapid engineering adjustments are paramount, as an adversary can persistently blind monitoring or configuration interfaces without possessing valid credentials or prior access to the network segment.\nThe attack vector relies entirely on remote network exposure of the vulnerable communication interface, requiring no authentication or privilege prerequisites. Because the system lacks adequate validation or resource management capabilities when processing incoming connection requests or protocol payloads, the vulnerable component succumbs to the disruption state immediately upon processing the attack payload. Consequently, organizations relying on the affected product face operational availability risks if exposed to untrusted networks.",
  "technicalDetails": "The vulnerability resides within the communication interface handler of PLCnext Engineer, specifically affecting the network service responsible for managing incoming client application connections. The root cause stems from insufficient error handling, inadequate input validation, or improper resource allocation within the service when parsing specific unauthenticated network traffic. As a result, the component fails to gracefully handle malformed or maliciously crafted interaction sequences, triggering a fatal exception or resource exhaustion state that crashes or hangs the underlying communication daemon.\nThe attack flow proceeds entirely over the network without requiring any user interaction or pre-existing authentication credentials. An unauthenticated remote attacker initiates communication with the exposed PLCnext Engineer communication port. By transmitting a specifically crafted sequence of packets or a targeted protocol payload, the adversary forces the vulnerable component into an unrecoverable error state. The payload behavior disrupts the internal state machine of the service, causing it to terminate unexpectedly or cease processing legitimate threads entirely.\nPost-exploitation impact is strictly limited to a denial of service, manifesting as a complete disruption of remote communication via the client application. Because the service crashes or hangs indefinitely, legitimate engineering workstations and clients are completely locked out from communicating with the device. The system does not recover autonomously; normal operational state and remote accessibility can only be restored via manual physical or out-of-band administrative intervention to restart the PLCnext service.\nThe vulnerability affects the network exposure of the PLCnext Engineer communication interface, making any deployment with direct internet connectivity or accessible via untrusted local area networks highly vulnerable. Since no privileges or authentication tokens are required to deliver the malicious payload, the attack surface encompasses any network path capable of reaching the device's designated listening ports."
}
CVE-2025-41770: PLCnext Engineer Unauthenticated Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere