CVE-2018-25112 HIGH

CVE-2018-25112: PHOENIX CONTACT: ILC 1x1 ETH Denial of Service

Vendor Phoenix Contact
Product ILC 131
Weakness CWE-770 · Uncontrolled resource consumption
Published June 4, 2025
Last update June 4, 2025

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large amounts of network traffic that needs to be handled by the ILC. This results in a Denial-of-Service of the device.

Key dates

02Disclosure timeline

June 4, 2025 CVE published
June 4, 2025 Record updated