LiveActive security incident?Get immediate response
CVE Record

CVE-2025-41769: Unauthenticated Buffer Overflow in PROFINET Service

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A flaw in the default PROFINET service could let an unauthenticated network attacker crash affected Phoenix Contact controllers or run arbitrary code. Successful compromise could disrupt industrial operations, alter controller behavior, or expose sensitive data. The supplied sources do not establish internet exposure or active exploitation.

Executive priority

Treat this as an urgent industrial-control risk. Immediately identify exposed listed devices, reduce network reachability, and obtain vendor-approved remediation. Coordinate changes with operations and safety teams because uncontrolled testing or firmware changes may interrupt production.

Technical view

CVE-2025-41769 is a CWE-120 buffer overflow reachable over the network without authentication, privileges, or user interaction. It carries CVSS 3.1 score 9.8. The bundle identifies multiple Phoenix Contact controller families with version 2019.0.4, but does not provide a complete affected-version range or a named fixed release.

Likely exposure

Exposure is most likely where listed Phoenix Contact devices run version 2019.0.4 with the default PROFINET service reachable from untrusted, corporate, or poorly segmented networks. The bundle does not confirm which deployments are externally reachable or whether other versions are affected.

Exploitation context

The vulnerability reportedly permits device reboot or arbitrary code execution remotely without authentication. CISA KEV status is false, and the supplied sources provide no evidence of active exploitation. That absence should not be interpreted as proof that exploitation is not occurring.

Researcher notes

The source bundle supports network-reachable, unauthenticated exploitation with high confidentiality, integrity, and availability impact. However, it does not include technical root-cause detail, proof of concept, active-exploitation evidence, a fixed version, or an unambiguous full version range. Validate product status directly against the referenced CSAF advisory.

Mitigation direction

  • Inventory listed Phoenix Contact products and record their exact firmware versions.
  • Review the vendor CSAF advisory for confirmed affected ranges, fixes, and supported upgrade paths.
  • Restrict PROFINET reachability to required trusted engineering and industrial network segments.
  • Monitor vendor guidance for updated remediation information before changing safety-critical controllers.

Validation and detection

  • Confirm each controller model and firmware version against the vendor CSAF product status.
  • Verify whether PROFINET is enabled and reachable from untrusted or non-operational networks.
  • Review network controls for unnecessary paths into affected industrial segments.
  • After remediation, confirm the installed version and required PROFINET functionality without disruptive security testing.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-120: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-41769 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CERTVDE
9.3CVSS 4.0CriticalCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCERTVDE

Vulnerability scoring details

Base CVSS 4.0 score

9.3Critical
CVSS 4.0 vector shape for CVE-2025-41769Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Phoenix ContactAXC F 11522019.0.4unaffected
Phoenix ContactAXC F 12522019.0.4unaffected
Phoenix ContactAXC F 21522019.0.4unaffected
Phoenix ContactAXC F 31522019.0.4unaffected
Phoenix ContactBPC 9102S2019.0.4unaffected
Phoenix ContactBPC 9202S2019.0.4unaffected
Phoenix ContactRFC 4072R2019.0.4unaffected
Phoenix ContactRFC 4072S2019.0.4unaffected
Phoenix ContactVL3 UPC 2440 EDGE2019.0.4unaffected
Phoenix ContactVPLCNEXT CONTROL 10002019.0.4unaffected
Phoenix ContactVPLCNEXT CONTROL 20002019.0.4unaffected
Phoenix ContactVPLCNEXT CONTROL 30002019.0.4unaffected
Phoenix ContactVPLCNEXT CONTROL 5002019.0.4unaffected
Phoenix ContactEPC 15022019.0.4unaffected
Phoenix ContactEPC 15222019.0.4unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.