SIMATIC CN 4100 Vulnerability

HIGH (8.1)

Threat Intelligence

Low Risk
EPSS Score: 0.04% chance of exploitation (percentile: 13%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The SIMATIC CN 4100 is a communication node used in process control technology. It stores sensitive information in its firmware, which could potentially be accessed and misused by an attacker.

Am I affected?

You're affected if you use A vulnerability. Specific version info not stated in the advisory. If you don't recognise this software, you're probably not affected.

How to fix

To fix this vulnerability, update to SIMATIC CN 4100 version V4.0.1 or later. You can download the latest version from:

  • Siemens Support: https://support.industry.siemens.com/cs/ww/en/view/109814144/
  • Siemens ProductCERT: https://cert-portal.siemens.com/productcert/html/ssa-416652.html

Immediate mitigations include:
* Restrict network access to your SIMATIC CN 4100 instance (firewall it from the public internet)
* Audit admin account activity for suspicious access patterns
* Monitor for unauthorized token creation

References