Vulnerability Description
A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Fl Switch 2708 Pn Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2708 Pn | - |
| Phoenixcontact | Fl Switch 2708 Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2708 | - |
| Phoenixcontact | Fl Switch 2608 Pn Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2608 Pn | - |
| Phoenixcontact | Fl Switch 2608 Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2608 | - |
| Phoenixcontact | Fl Switch 2516 Pn Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2516 Pn | - |
| Phoenixcontact | Fl Switch 2516 Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2516 | - |
| Phoenixcontact | Fl Switch 2514-2Sfp Pn Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2514-2Sfp Pn | - |
| Phoenixcontact | Fl Switch 2514-2Sfp Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2514-2Sfp | - |
| Phoenixcontact | Fl Switch 2512-2Gc-2Sfp Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2512-2Gc-2Sfp | - |
| Phoenixcontact | Fl Switch 2508 Pn Firmware | < 3.50 |
| Phoenixcontact | Fl Switch 2508 Pn | - |
Related Weaknesses (CWE)
References
- https://certvde.com/de/advisories/VDE-2025-071Third Party Advisory
FAQ
What is CVE-2025-41693?
CVE-2025-41693 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management func...
How severe is CVE-2025-41693?
CVE-2025-41693 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-41693?
Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Fl Switch 2708 Pn Firmware, Phoenixcontact Fl Switch 2708 Pn, Phoenixcontact Fl Switch 2708 Firmware, Phoenixcontact Fl Switch 2708, Phoenixcontact Fl Switch 2608 Pn Firmware.