The CVSS 7.5 score for CVE-2025-41770 — an unauthenticated denial-of-service in Phoenix Contact's PLCnext Engineer — measures correctly but misleads in industrial environments. The vulnerability allows an attacker to crash the PLCnext Engineer service with a single crafted packet. The catch: the service does not recover automatically. Someone must manually restart it. In an OT context, that requirement transforms a routine DoS into an operational crisis.

Here's why. PLCnext Engineer isn't a background service — it's the primary interface for configuring, monitoring, and diagnostics of PLCnext controllers. When it goes down, operators lose real-time visibility into process state. Any automated responses that depend on engineering workstation communication behave unpredictably. Safety instrumented functions receiving that data feed may receive stale inputs or none at all. The manual restart requirement doesn't just extend downtime — it creates a coordination gap where operations, maintenance, and security are working from different information pictures until someone physically accesses the device to restart the service.

In a production facility, that restart could require a technician to travel to a remote site, coordinate with operations for a controlled shutdown, and wait for a maintenance window. Downtime extends from minutes to hours or days. The EPSS score of 0.00386 reflects opportunistic internet scanning, not targeted attacks against specific industrial facilities. If your PLCnext Engineer management interface is accessible through corporate networks, VPN tunnels, or any client machine on the same network segment, the exploitation likelihood for your organization is decoupled from the global EPSS calculation.

Check your exposure: map whether the PLCnext Engineer interface is segmented from the control plane and corporate IT. Identify every client machine on network segments that can reach it — any compromised endpoint becomes a potential DoS trigger. Review your mean time to response for engineering support and whether your maintenance window policies accommodate this failure mode. The manual restart requirement creates a predictable window of operational vulnerability that could be exploited as a distraction or prelude to secondary attack activity. This isn't a scoring problem — it's a blast radius problem, and the CVSS metric doesn't model it.