CVE-2026-22925
- EPSS 0.32%
- Veröffentlicht 12.05.2026 08:20:56
- Zuletzt bearbeitet 29.06.2026 14:05:43
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the service unavaila...
CVE-2026-22924
- EPSS 0.3%
- Veröffentlicht 12.05.2026 08:20:55
- Zuletzt bearbeitet 29.06.2026 14:06:00
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disru...
CVE-2026-2673
- EPSS 0.44%
- Veröffentlicht 13.03.2026 13:23:00
- Zuletzt bearbeitet 05.06.2026 19:48:51
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may...
CVE-2025-14831
- EPSS 0.64%
- Veröffentlicht 09.02.2026 14:51:32
- Zuletzt bearbeitet 01.09.2026 12:17:17
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject a...
- EPSS 0.2%
- Veröffentlicht 26.01.2026 19:58:32
- Zuletzt bearbeitet 01.09.2026 13:18:06
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack bu...
CVE-2025-40941
- EPSS 0.28%
- Veröffentlicht 09.12.2025 10:44:40
- Zuletzt bearbeitet 07.10.2026 20:10:01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood ...
CVE-2025-40940
- EPSS 0.36%
- Veröffentlicht 09.12.2025 10:44:39
- Zuletzt bearbeitet 07.10.2026 20:10:01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling across protocol versions. This...
CVE-2025-40939
- EPSS 0.21%
- Veröffentlicht 09.12.2025 10:44:37
- Zuletzt bearbeitet 07.10.2026 20:10:01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that c...
CVE-2025-40938
- EPSS 0.37%
- Veröffentlicht 09.12.2025 10:44:36
- Zuletzt bearbeitet 07.10.2026 20:10:01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s c...
CVE-2025-40937
- EPSS 0.57%
- Veröffentlicht 09.12.2025 10:44:35
- Zuletzt bearbeitet 07.10.2026 20:10:01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow an authentic...