A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-313488.pdf | Patch Vendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-313488.pdf | Patch Vendor Advisory |
Configurations
History
18 Feb 2026, 18:23
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Siemens simatic Cn 4100 Firmware
|
|
| CPE | cpe:2.3:o:siemens:simatic_cn_4100_firmware:*:*:*:*:*:*:*:* |
21 Nov 2024, 07:56
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
| References | () https://cert-portal.siemens.com/productcert/pdf/ssa-313488.pdf - Patch, Vendor Advisory |
18 Jul 2023, 15:53
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Siemens
Siemens simatic Cn 4100 |
|
| References | (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-313488.pdf - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:siemens:simatic_cn_4100:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
| CWE | NVD-CWE-noinfo |
11 Jul 2023, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-07-11 10:15
Updated : 2026-02-18 18:23
NVD link : CVE-2023-29130
Mitre link : CVE-2023-29130
CVE.ORG link : CVE-2023-29130
JSON object : View
Products Affected
siemens
- simatic_cn_4100_firmware
CWE
