PT-2023-4084 · Siemens · Simatic Cn 4100

Published

2023-07-11

·

Updated

2023-07-18

·

CVE-2023-29131

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC CN 4100 versions prior to V2.5
Description A vulnerability has been identified in the SIMATIC CN 4100, related to an incorrect default value in the SSH configuration. This issue could allow an attacker to bypass network isolation. The vulnerability is associated with incorrect default access settings, which can be exploited by a remote attacker.
Recommendations For versions prior to V2.5, update to version V2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH configuration to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2023-04384
CVE-2023-29131

Affected Products

Simatic Cn 4100