CRITICAL🇵🇱 Wersja polska

CVE-2025-40938

CVSS 9.2v4.0pub. 2025-12-09upd. 2025-12-10

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.

🤖 AI Analysis
How it works

In accordance with CWE-798 (Use of Hard-coded Credentials), the manufacturer placed sensitive data in the device firmware in a static form — accessible to anyone who gains access to the firmware image or the device itself. An attacker who recovers this information can use it for unauthorized access or further compromise of the system. Because the data is hardcoded, there is no way for an end user to change it without a software update.

Impact

An attacker can read credentials hardcoded in the firmware or other sensitive information and use it to take control of the device, affecting its confidentiality, integrity, and availability.

Mitigation & patch

The SIMATIC CN 4100 device firmware should be updated to version V4.0.1 or later. Detailed instructions are available in the Siemens security advisory SSA-416652 at: https://cert-portal.siemens.com/productcert/html/ssa-416652.html

Who is affected

Siemens SIMATIC CN 4100 — all firmware versions below V4.0.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Siemens Simatic Cn 4100

    HW
    Siemens
    all versions
  • Siemens Simatic Cn 4100 Firmware

    OS
    Siemens
    < 4.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-32740CRITICAL9.8PL ✓same product

Ukryte dane uwierzytelniające w Siemens SIMATIC CN 4100 (hardcoded credentials)

CVE-2024-32741CRITICAL10.0PL ✓same product

Zakodowane na stałe hasło root w Siemens SIMATIC CN 4100

CVE-2023-49621CRITICAL9.8PL ✓same product

Siemens SIMATIC CN 4100 – domyślne dane uwierzytelniające z uprawnieniami administratora

CVE-2023-29130CRITICAL9.9PL ✓same product

Privilege escalation w Siemens SIMATIC CN 4100 — błędna kontrola dostępu

CVE-2026-22924HIGH8.8same product

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does no...