CVE-2025-41693: Authenticated Denial-of-Service via SSH
A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41693?
CVE-2025-41693 has a low severity level, allowing a low privileged remote attacker to execute commands directly after login.
How do I fix CVE-2025-41693?
To fix CVE-2025-41693, update the affected Phoenix Contact firmware to version 3.50 or higher.
What systems are affected by CVE-2025-41693?
Affected systems include specific Phoenix Contact FL Switch models with firmware versions below 3.50.
What are the implications of CVE-2025-41693?
CVE-2025-41693 may lead to performance issues in management functions due to resource consumption after unauthorized command execution.
Can CVE-2025-41693 be exploited locally?
CVE-2025-41693 primarily allows remote exploitation, requiring the attacker to have low privileges.