Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20396 | A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device. |
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-054 |
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device. | |
| Title | Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-07-08T14:28:20.367Z
Reserved: 2025-04-16T11:17:48.307Z
Link: CVE-2025-41668
Updated: 2025-07-08T14:23:23.994Z
Status : Deferred
Published: 2025-07-08T07:15:25.987
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41668
No data.
OpenCVE Enrichment
No data.
EUVD