A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.
In accordance with CWE-798 (Use of Hard-coded Credentials), the manufacturer placed sensitive data in the device firmware in a static form — accessible to anyone who gains access to the firmware image or the device itself. An attacker who recovers this information can use it for unauthorized access or further compromise of the system. Because the data is hardcoded, there is no way for an end user to change it without a software update.
An attacker can read credentials hardcoded in the firmware or other sensitive information and use it to take control of the device, affecting its confidentiality, integrity, and availability.
The SIMATIC CN 4100 device firmware should be updated to version V4.0.1 or later. Detailed instructions are available in the Siemens security advisory SSA-416652 at: https://cert-portal.siemens.com/productcert/html/ssa-416652.html
Siemens SIMATIC CN 4100 — all firmware versions below V4.0.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Simatic Cn 4100
HWSiemensall versionsSiemens Simatic Cn 4100 Firmware
OSSiemens< 4.0.1
Related vulnerabilities
Ukryte dane uwierzytelniające w Siemens SIMATIC CN 4100 (hardcoded credentials)
Zakodowane na stałe hasło root w Siemens SIMATIC CN 4100
Siemens SIMATIC CN 4100 – domyślne dane uwierzytelniające z uprawnieniami administratora
Privilege escalation w Siemens SIMATIC CN 4100 — błędna kontrola dostępu
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does no...