A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-050/ |
|
History
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation. | |
| Title | Untrusted Search Path | |
| First Time appeared |
Phoenix Contact
Phoenix Contact axc F 1152 Phoenix Contact axc F 1252 Phoenix Contact axc F 2000 Ea Phoenix Contact axc F 2152 Phoenix Contact axc F 3152 Phoenix Contact bpc 9102s Phoenix Contact epc 1522 Phoenix Contact rfc 4072r Phoenix Contact rfc 4072s Phoenix Contact vl3 Upc 2440 Edge Phoenix Contact vplcnext Control 1000 Phoenix Contact vplcnext Control 2000 Phoenix Contact vplcnext Control 3000 Phoenix Contact vplcnext Control 500 |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:phoenix_contact:axc_f_1152:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_1252:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_2000_ea:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_2152:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_3152:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:bpc_9102s:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:epc_1522:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:rfc_4072r:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:rfc_4072s:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vl3_upc_2440_edge:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_1000:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_2000:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_3000:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_500:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact axc F 1152 Phoenix Contact axc F 1252 Phoenix Contact axc F 2000 Ea Phoenix Contact axc F 2152 Phoenix Contact axc F 3152 Phoenix Contact bpc 9102s Phoenix Contact epc 1522 Phoenix Contact rfc 4072r Phoenix Contact rfc 4072s Phoenix Contact vl3 Upc 2440 Edge Phoenix Contact vplcnext Control 1000 Phoenix Contact vplcnext Control 2000 Phoenix Contact vplcnext Control 3000 Phoenix Contact vplcnext Control 500 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T07:17:43.775Z
Reserved: 2025-04-16T11:17:48.308Z
Link: CVE-2025-41670
No data.
Status : Received
Published: 2026-05-27T08:16:39.920
Modified: 2026-05-27T08:16:39.920
Link: CVE-2025-41670
No data.
OpenCVE Enrichment
No data.