CVE-2025-41769: Unauthenticated Buffer Overflow in PROFINET Service
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Security readout for executives and security teams
Plain-English summary
A flaw in the default PROFINET service could let an unauthenticated network attacker crash affected Phoenix Contact controllers or run arbitrary code. Successful compromise could disrupt industrial operations, alter controller behavior, or expose sensitive data. The supplied sources do not establish internet exposure or active exploitation.
Executive priority
Treat this as an urgent industrial-control risk. Immediately identify exposed listed devices, reduce network reachability, and obtain vendor-approved remediation. Coordinate changes with operations and safety teams because uncontrolled testing or firmware changes may interrupt production.
Technical view
CVE-2025-41769 is a CWE-120 buffer overflow reachable over the network without authentication, privileges, or user interaction. It carries CVSS 3.1 score 9.8. The bundle identifies multiple Phoenix Contact controller families with version 2019.0.4, but does not provide a complete affected-version range or a named fixed release.
Likely exposure
Exposure is most likely where listed Phoenix Contact devices run version 2019.0.4 with the default PROFINET service reachable from untrusted, corporate, or poorly segmented networks. The bundle does not confirm which deployments are externally reachable or whether other versions are affected.
Exploitation context
The vulnerability reportedly permits device reboot or arbitrary code execution remotely without authentication. CISA KEV status is false, and the supplied sources provide no evidence of active exploitation. That absence should not be interpreted as proof that exploitation is not occurring.
Researcher notes
The source bundle supports network-reachable, unauthenticated exploitation with high confidentiality, integrity, and availability impact. However, it does not include technical root-cause detail, proof of concept, active-exploitation evidence, a fixed version, or an unambiguous full version range. Validate product status directly against the referenced CSAF advisory.
Mitigation direction
Inventory listed Phoenix Contact products and record their exact firmware versions.
Review the vendor CSAF advisory for confirmed affected ranges, fixes, and supported upgrade paths.
Restrict PROFINET reachability to required trusted engineering and industrial network segments.
Monitor vendor guidance for updated remediation information before changing safety-critical controllers.
Validation and detection
Confirm each controller model and firmware version against the vendor CSAF product status.
Verify whether PROFINET is enabled and reachable from untrusted or non-operational networks.
Review network controls for unnecessary paths into affected industrial segments.
After remediation, confirm the installed version and required PROFINET functionality without disruptive security testing.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-120: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.