PT-2025-49843 · Siemens · Simatic Cn 4100

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-40938

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC CN 4100 versions prior to 4.0.1
Description The device stores sensitive information in its firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.
Recommendations Update to version 4.0.1 or later.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2026-00141
CVE-2025-40938

Affected Products

Simatic Cn 4100