CVE-2026-22925
- EPSS 0.04%
- Veröffentlicht 12.05.2026 08:20:56
- Zuletzt bearbeitet 12.05.2026 14:19:41
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the service unavaila...
CVE-2026-22924
- EPSS 0.04%
- Veröffentlicht 12.05.2026 08:20:55
- Zuletzt bearbeitet 12.05.2026 14:19:41
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disru...
CVE-2026-2673
- EPSS 0.02%
- Veröffentlicht 13.03.2026 13:23:00
- Zuletzt bearbeitet 13.05.2026 19:17:04
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may...
CVE-2025-14831
- EPSS 0.06%
- Veröffentlicht 09.02.2026 14:51:32
- Zuletzt bearbeitet 14.05.2026 23:16:36
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject a...
- EPSS 0.01%
- Veröffentlicht 26.01.2026 19:58:32
- Zuletzt bearbeitet 12.05.2026 13:17:30
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack bu...
CVE-2025-40941
- EPSS 0.03%
- Veröffentlicht 09.12.2025 10:44:40
- Zuletzt bearbeitet 10.12.2025 21:32:01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood ...
CVE-2025-40940
- EPSS 0.03%
- Veröffentlicht 09.12.2025 10:44:39
- Zuletzt bearbeitet 10.12.2025 21:34:59
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling across protocol versions. This...
CVE-2025-40939
- EPSS 0.04%
- Veröffentlicht 09.12.2025 10:44:37
- Zuletzt bearbeitet 16.12.2025 17:30:28
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that c...
CVE-2025-40938
- EPSS 0.04%
- Veröffentlicht 09.12.2025 10:44:36
- Zuletzt bearbeitet 10.12.2025 21:36:44
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s c...
CVE-2025-40937
- EPSS 0.07%
- Veröffentlicht 09.12.2025 10:44:35
- Zuletzt bearbeitet 10.12.2025 21:37:50
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow an authentic...