Simatic cn 4100 firmware
This hub aggregates every CVE we track for Simatic cn 4100 firmware, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
5
Critical
9
High
1
In CISA KEV
Severity distribution
HIGH9MEDIUM5CRITICAL5
Monthly trend
0
0
0
0
0
0
0
0
0
1
1
0
0
0
5
0
0
1
1
2
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Simatic cn 4100 firmware.
- CVE-2026-22925A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This c...7.5
- CVE-2026-22924A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhausti...9.1
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeKEV7.8
- CVE-2026-2673OpenSSL TLS 1.3 server may choose unexpected key agreement group6.5
- CVE-2025-40941A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access t...4.3
- CVE-2025-40940A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable ...4.9
- CVE-2025-40939A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with p...4.6
- CVE-2025-40938A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse t...8.1
- CVE-2025-40937A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of...8.3
- CVE-2025-38502bpf: Fix oob access in cgroup local storage7.8
- CVE-2025-40593A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This...6.5
- CVE-2024-32742A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially mi...7.6
- CVE-2024-32741A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot l...10.0
- CVE-2024-32740A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise...9.8
- CVE-2023-49621A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges....9.8
Product normalization is registry-driven with AI assist and human review. How it works