CVE-2025-41647 Details
Description
A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.
A vulnerability in Lenze PLC Designer V4, specifically in version 4.0.0, allows local, low-privileged attackers to view the passwords of connected controllers in plain text. This issue arises from an improper implementation that exposes passwords under certain conditions, but only in the software interface, not on the devices themselves. The vulnerability is limited to use with c430, c520, and c550 controllers.
Users are strongly advised to update to PLC Designer V4 version 4.0.1, where this vulnerability has been fixed. Lenze also recommends using the tool only in closed and protected security zones to prevent unauthorized viewing of passwords during entry.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2025CISA-ADP
Assessed Jun 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2025-043/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lenze PLC Designer V4 | 4.0.0 (semver) |
CPE
Remediation
| |
| Lenze c430 | All versions |
CPE
Remediation
| |
| Lenze c520 | All versions |
CPE
Remediation
| |
| Lenze c550 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | New CVE Received | [email protected] |
Volerion