A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling across protocol versions. This could allow an attacker to access sensitive data, potentially leading to a breach of confidentiality.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-416652.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
10 Dec 2025, 21:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:siemens:simatic_cn_4100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_cn_4100:-:*:*:*:*:*:*:* |
|
| References | () https://cert-portal.siemens.com/productcert/html/ssa-416652.html - Vendor Advisory | |
| First Time |
Siemens
Siemens simatic Cn 4100 Firmware Siemens simatic Cn 4100 |
09 Dec 2025, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 16:17
Updated : 2025-12-10 21:34
NVD link : CVE-2025-40940
Mitre link : CVE-2025-40940
CVE.ORG link : CVE-2025-40940
JSON object : View
Products Affected
siemens
- simatic_cn_4100
- simatic_cn_4100_firmware
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
