Simatic Cn 4100 Firmware
19 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Simatic Cn 4100 Firmware, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
Simatic Cn 4100 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 5 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 1 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High9
- Medium5
Latest CVEs
The 15 most recently published vulnerabilities affecting Simatic Cn 4100 Firmware.
- CVE-2026-22925A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This c...7.5
- CVE-2026-22924A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhausti...9.1
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
- CVE-2026-2673OpenSSL TLS 1.3 server may choose unexpected key agreement group6.5
- CVE-2025-40941A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access t...4.3
- CVE-2025-40940A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable ...4.9
- CVE-2025-40939A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with p...4.6
- CVE-2025-40938A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse t...8.1
- CVE-2025-40937A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of...8.3
- CVE-2025-38502bpf: Fix oob access in cgroup local storage7.8
- CVE-2025-40593A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This...6.5
- CVE-2024-32742A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially mi...7.6
- CVE-2024-32741A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot l...10.0
- CVE-2024-32740A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise...9.8
- CVE-2023-49621A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges....9.8
Product grouping is registry-driven, with AI assist and human review. How it works