PT-2025-49842 · Siemens · Simatic Cn 4100
CVE-2025-40937
·
Publicado
2025-12-09
·
Atualizado
2025-12-09
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SIMATIC CN 4100 versions prior to 4.0.1
Description
The application does not properly validate input parameters in its REST API, leading to improper handling of unexpected arguments. This could allow an authenticated attacker to execute arbitrary code with limited privileges. The vulnerable component is the REST API, specifically its handling of input parameters.
Recommendations
Update to version 4.0.1 or later.
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simatic Cn 4100