PLCnext Trust Break Can Reach Persistent Control Logic
A low-privilege web account on a PLC should not be able to reach the trust checks that protect the controller itself. Here, that boundary fails, so an Engineer role can escalate to root and get to the material used to validate or sign control logic; cleanup of the original account does not undo that kind of device-level tampering.
Nozomi says the issue affects Phoenix Contact PLCnext AXC F 3152 firmware 2024.0.6, and Phoenix Contact says multiple PLCnext models are affected. The finding sits in the web interface and the vendor has already released updated firmware, which matters for OT teams because the blast radius is not just one controller model but any PLCnext or CODESYS-based device that stores trust on-box and exposes a management role.