CVE-2025-41669
CVSS 8.8 HIGH: the Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device… EPSS 0.2% (12º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
Un account web con privilegi bassi su un PLC non dovrebbe essere in grado di raggiungere i controlli di trust che proteggono il controller stesso. Qui, quel confine fallisce, quindi un ruolo Engineer può scalare a root e accedere al materiale usato per validare o firmare la logica di controllo; la pulizia dell'account originale non annulla questo tipo di manomissione a livello di dispositivo.
1 fonte · 2 giu
CVSS 8.8 HIGH: the Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device… EPSS 0.2% (12º percentile).
Industrial Cyber
Privilege-escalation flaws in Phoenix Contact PLCnext controllers could enable attackers to gain root access - Industrial Cyber
Nozomi warns that privilege-escalation flaws in Phoenix Contact PLCnext controllers could enable attackers to gain root access.
originalePart of the PlainSec briefing for 2026-06-02
Every edition of this story: PLCnext Trust Break Può Raggiungere Logica di Controllo Persistente