CVE-2025-40593
- EPSS 0.07%
- Published 08.07.2025 10:34:51
- Last modified 21.08.2025 15:12:53
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This could allow an attacker to cause a denial of service...
CVE-2024-32742
- EPSS 0.14%
- Published 14.05.2024 16:17:12
- Last modified 20.08.2025 18:05:14
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system an...
CVE-2024-32740
- EPSS 0.86%
- Published 14.05.2024 16:17:11
- Last modified 20.08.2025 18:09:35
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.
- EPSS 0.74%
- Published 14.05.2024 16:17:11
- Last modified 26.08.2025 20:16:23
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to ...
CVE-2023-49252
- EPSS 0.23%
- Published 09.01.2024 10:15:20
- Last modified 21.11.2024 08:33:07
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of service condition.
CVE-2023-49621
- EPSS 0.15%
- Published 09.01.2024 10:15:20
- Last modified 21.11.2024 08:33:38
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain comple...
CVE-2023-49251
- EPSS 0.43%
- Published 09.01.2024 10:15:19
- Last modified 21.11.2024 08:33:07
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to rem...
- EPSS 0.2%
- Published 11.07.2023 10:15:10
- Last modified 21.11.2024 07:56:35
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerabil...
- EPSS 0.02%
- Published 11.07.2023 10:15:10
- Last modified 21.11.2024 07:56:35
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.