Siemens
Siemens Simatic CN 4100 Firmware: vulnerabilities and CVEs
Siemens Simatic CN 4100 Firmware has 20 published vulnerabilities, 9 of them in the last 12 months. 7 are rated critical and 2 are listed by CISA as actively exploited.
CVEs20
Last 12 months9
Critical7
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39682 | Critical (9.8) | 2.9% | ⚠ Active exploitation | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) -… |
| CVE-2026-31431 | High (7.8) | 3.4% | ⚠ Active exploitation | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22925 | High (8.7) | 0.32% | — | May 12, 2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker… |
| CVE-2026-22924 | High (8.8) | 0.30% | — | May 12, 2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This… |
| CVE-2026-31431 | High (7.8) | 3.4% | ⚠ Active exploitation | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2026-2673 | Medium (6.5) | 0.49% | — | Mar 13, 2026 | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A… |
| CVE-2025-40941 | Medium (5.3) | 0.28% | — | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful… |
| CVE-2025-40940 | Medium (6.9) | 0.37% | — | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling… |
| CVE-2025-40939 | Medium (5.1) | 0.21% | — | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the… |
| CVE-2025-40938 | Critical (9.2) | 0.38% | — | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information,… |
| CVE-2025-40937 | High (8.7) | 0.59% | — | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments.… |
| CVE-2025-39682 | Critical (9.8) | 2.9% | ⚠ Active exploitation | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) -… |
| CVE-2025-38502 | High (7.1) | 0.17% | — | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given… |
| CVE-2025-40593 | High (7.1) | 0.36% | — | Jul 8, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This could allow an… |
| CVE-2024-32742 | High (7.6) | 0.39% | — | May 14, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for… |
| CVE-2024-32741 | Critical (10) | 0.63% | — | May 14, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by… |
| CVE-2024-32740 | Critical (9.8) | 0.70% | — | May 14, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or… |
| CVE-2023-49621 | Critical (9.8) | 0.60% | — | Jan 9, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use… |
| CVE-2023-49252 | High (7.5) | 0.57% | — | Jan 9, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of… |
| CVE-2023-49251 | High (8.8) | 0.53% | — | Jan 9, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device.… |
| CVE-2023-29131 | Critical (10) | 0.42% | — | Jul 11, 2023 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation. |
| CVE-2023-29130 | Critical (10) | 0.56% | — | Jul 11, 2023 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.