Phoenix Contact AXC F 1152
cpe:2.3:h:phoenixcontact:axc_f_1152:*:*:*:*:*:*:*, +1 more
- < 2025.0.2
A vulnerability exists in Phoenix Contact PLCnext devices, specifically in the AXC F 1152, AXC F 2152, AXC F 3152, BPC 9102S, and RFC 4072S models, all running versions prior to 2025.0.2. The issue arises from incorrect default permissions on a configuration file, allowing low-privileged remote attackers to manipulate the watchdog feature and force the device to reboot.
Exploitation of this vulnerability causes a denial-of-service condition by forcing the affected device to reboot, disrupting any ongoing processes or operations.
Users are advised to update to the latest firmware version 2025.0.2. Phoenix Contact recommends always using an up-to-date version of PLCnext Engineer.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.