Impact
The vulnerability is a stack-based buffer overflow (CWE‑120) in the PROFINET service of Phoenix Contact industrial controllers when running the default configuration. An unauthenticated remote attacker can exploit the overflow to trigger a device reboot or to execute arbitrary machine code, thereby compromising confidentiality, integrity, and availability of the system.
Affected Systems
The affected devices include several Phoenix Contact series such as the AXC F 1152, AXC F 1252, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, EPC 1502, EPC 1522, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, and VPLCNext CONTROL series (1000, 2000, 3000, 500). The vulnerability exists in the firmware of these units, with specific vulnerable versions not listed in the advisory.
Risk and Exploitability
The CVSS score of 9.3 signals critical severity, and the lack of an EPSS rating or KEV listing does not diminish the risk because the flaw permits unauthenticated access over the PROFINet protocol. Exploitation requires network connectivity to the device and the ability to send malformed Profinet packets; the attacker can cause a reboot or gain complete code execution, making this a high‑impact threat that warrants urgent attention.
OpenCVE Enrichment