Impact
The vulnerability is an unauthenticated denial‑of‑service flaw in the PLCnext Engineer communication interface of certain Phoenix Contact devices. An attacker can send crafted requests that cause the PLCnext service to hang, preventing new connections until the service is manually restarted. The weakness, identified as CWE‑770, stems from insufficient protection against resource exhaustion, resulting in a complete loss of network service for the affected controller. This impacts availability for anyone relying on the device to communicate with the PLCnext Engineer tool, and the effect can propagate to downstream automation processes that depend on that connection.
Affected Systems
Affected products are Phoenix Contact PLCnext devices running firmware on the AXC F 1152, AXC F 1252, AXC F 2000 EA, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, Catan C1, EPC 1502, EPC 1522, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNEXT CONTROL 1000, 2000, 3000, and 500 lines. The vulnerability applies to any device that uses the PLCnext Engineer communication interface; specific firmware versions were not enumerated but all pre‑patch releases are likely affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. Although an EPSS score is not available, the lack of a KEV listing suggests no confirmed exploits have been observed yet, but the high CVSS and unauthenticated nature mean the risk remains significant. The most likely attack vector is remote over the network, with an adversary simply sending a malicious payload to the exposed interface to trigger the DoS. Because authentication is not required, any host that can reach the PLCnext service can execute the flaw, making it broadly exploitable within an organization’s network.
OpenCVE Enrichment