Phoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLC
Description
An unauthenticated remote attacker can modify applications on Phoenix Contact classic line PLCs due to missing integrity check during code download.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated remote attacker can modify applications on Phoenix Contact classic line PLCs due to missing integrity check during code download.
Vulnerability
Phoenix Contact classic line PLCs are affected by a vulnerability that allows the download of code without an integrity check. The advisory does not specify exact firmware versions, but all classic line controllers are potentially impacted. The vulnerability is present in the device's firmware handling of application downloads from engineering tools such as the Automation Worx Software Suite [1].
Exploitation
An unauthenticated attacker with network access to the PLC can exploit this vulnerability by sending modified application code to the device. No authentication is required, and the attacker only needs to be able to communicate with the PLC over the network. The attack does not require any user interaction or prior access [1].
Impact
Successful exploitation allows the attacker to modify some or all applications running on the PLC. This can lead to arbitrary code execution, disruption of industrial processes, and potential safety risks. The attacker gains full control over the modified applications [1].
Mitigation
No firmware patch has been released. Mitigation relies on operational measures: operate the PLCs in closed industrial networks, use firewalls to segment OT zones, protect remote connections with VPN, and disable OT communication protocols if they are not required. Project data should only be transferred in protected environments [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
19- Range: all
- PHOENIX CONTACT/AXC 1050v5Range: all
- PHOENIX CONTACT/AXC 1050 XCv5Range: all
- PHOENIX CONTACT/AXC 3050v5Range: all
- PHOENIX CONTACT/Config+v5Range: all
- PHOENIX CONTACT/FC 350 PCI ETHv5Range: all
- PHOENIX CONTACT/ILC1x0v5Range: all
- PHOENIX CONTACT/ILC1x1v5Range: all
- PHOENIX CONTACT/ILC 3xxv5Range: all
all+ 1 more
- (no CPE)range: all
- (no CPE)range: all
- Range: all
- PHOENIX CONTACT/PC WORX RT BASICv5Range: all
- PHOENIX CONTACT/RFC 430 ETH-IBv5Range: all
- PHOENIX CONTACT/RFC 450 ETH-IBv5Range: all
- PHOENIX CONTACT/RFC 460R PN 3TXv5Range: all
- PHOENIX CONTACT/RFC 470S PN 3TXv5Range: all
- PHOENIX CONTACT/RFC 480S PN 4TXv5Range: all
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.