« Volver al listado

Siemens

Siemens Simatic CN 4100 Firmware: vulnerabilidades y CVE

Siemens Simatic CN 4100 Firmware tiene 20 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 7 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE20
Últimos 12 meses9
Críticas7
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-39682Crítica (9.8)2.9%⚠ Explotación activa5 sept 2025
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) -…
CVE-2026-31431Alta (7.8)3.4%⚠ Explotación activa22 abr 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-22925Alta (8.7)0.32%—12 may 2026
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker…
CVE-2026-22924Alta (8.8)0.30%—12 may 2026
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This…
CVE-2026-31431Alta (7.8)3.4%⚠ Explotación activa22 abr 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…
CVE-2026-2673Media (6.5)0.49%—13 mar 2026
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A…
CVE-2025-40941Media (5.3)0.28%—9 dic 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful…
CVE-2025-40940Media (6.9)0.37%—9 dic 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling…
CVE-2025-40939Media (5.1)0.21%—9 dic 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the…
CVE-2025-40938Crítica (9.2)0.38%—9 dic 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information,…
CVE-2025-40937Alta (8.7)0.59%—9 dic 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments.…
CVE-2025-39682Crítica (9.8)2.9%⚠ Explotación activa5 sept 2025
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) -…
CVE-2025-38502Alta (7.1)0.17%—16 ago 2025
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given…
CVE-2025-40593Alta (7.1)0.36%—8 jul 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This could allow an…
CVE-2024-32742Alta (7.6)0.39%—14 may 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for…
CVE-2024-32741Crítica (10)0.63%—14 may 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by…
CVE-2024-32740Crítica (9.8)0.70%—14 may 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or…
CVE-2023-49621Crítica (9.8)0.60%—9 ene 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use…
CVE-2023-49252Alta (7.5)0.57%—9 ene 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of…
CVE-2023-49251Alta (8.8)0.53%—9 ene 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device.…
CVE-2023-29131Crítica (10)0.42%—11 jul 2023
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
CVE-2023-29130Crítica (10)0.56%—11 jul 2023
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1499.004 Application or System Exploitation3
  3. T1059 Command and Scripting Interpreter2
  4. T1068 Exploitation for Privilege Escalation2
  5. T1210 Exploitation of Remote Services2
  6. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Siemens