Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
Multiple improper input validation vulnerabilities in PLCnext firmware (versions 2019.0.4 through 2026.0.2) affect buffer handling, resource consumption, and SQL query processing. Unauthenticated attackers on the network can trigger denial of service, execute unexpected system behavior, or perform unauthorized SQL operations. These vulnerabilities impact availability, integrity, and confidentiality of PLCnext Control devices. Firmware version 2026.0.3 resolves all issues; EPC 1502 and EPC 1522 have no patch planned.
- Network access to PLCnext device (HTTP/HTTPS ports)
- No authentication or credentials required
- Device running firmware version 2019.0.4 through 2026.0.2
Patching may require device reboot — plan for process interruption
/api/v1/advisories/a3f0e87b-28f4-4544-9427-29ed518e3334Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.