SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2025-41647

A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.

MEDIUM 5.5EPSS 0.09%

Does this matter?

Lower severity and a low EPSS score (0.09%). Track it; it rarely justifies an emergency change on its own.

Description

A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.09% probability · 1th percentile
CISA KEV
Not listed
Weakness
CWE-312
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.