<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PLCnext Engineer - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/plcnext-engineer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 08:39:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/plcnext-engineer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Denial-of-Service Vulnerability in PLCnext Engineer</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2025-41770-plcnext-dos/</link><pubDate>Wed, 12 Aug 2026 08:39:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2025-41770-plcnext-dos/</guid><description>An unauthenticated remote denial-of-service vulnerability in the Phoenix Contact PLCnext Engineer communication interface allows attackers to crash the service, requiring manual intervention.</description><content:encoded><![CDATA[<p>CVE-2025-41770 is a high-severity denial-of-service vulnerability discovered in the communication interface of Phoenix Contact's PLCnext Engineer software. The flaw allows an unauthenticated remote attacker to send specially crafted network traffic to the communication port used by the client application. Successful exploitation of this vulnerability interrupts the service, rendering the device unreachable via the PLCnext interface until a manual restart of the affected service is performed by an administrator. Because this vulnerability is accessible remotely without authentication, it presents a risk to industrial control environments where uptime is critical. Defenders should restrict network access to the PLCnext Engineer communication port to authorized management segments only.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a complete loss of service for the affected PLCnext Engineer communication interface. In an industrial or production environment, this interruption prevents operators from interacting with the PLCnext device via the client application, potentially impeding safety, monitoring, or control functions. The impact is persistent, requiring manual restart of the service, which could lead to significant operational downtime depending on the ease of physical or administrative access to the affected hardware.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement network segmentation to restrict access to the PLCnext Engineer communication port to known, trusted engineering workstations.</li>
<li>Monitor logs for repeated connection attempts or abnormal communication patterns directed at the PLCnext Engineer communication port.</li>
<li>Review Phoenix Contact security advisories for official patch releases and apply them to all vulnerable PLCnext Engineer deployments.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>dos</category><category>industrial-control-system</category><category>vulnerability</category></item></channel></rss>