Phoenix Contact AXC F 1152
cpe:2.3:h:phoenixcontact:axc_f_1152:*:*:*:*:*:*:*, +1 more
- < 2025.0.2
A vulnerability exists in Phoenix Contact PLCnext firmware versions prior to 2025.0.2. It allows low-privileged remote attackers with file access to replace critical files or folders used by the service security-profile. This manipulation can grant read, write, and execute access to any file on the device.
Exploitation of this vulnerability could lead to unauthorized access and manipulation of critical system files, potentially compromising the availability, integrity, and confidentiality of the PLCnext Control.
Users are advised to update to the latest firmware version 2025.0.2. Phoenix Contact recommends always using an up-to-date version of PLCnext Engineer.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.