cbcvebase.
CVE-2023-29130
published 2023-07-11

CVE-2023-29130: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files…

PriorityP263critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.56%
42.9th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_cn_4100
siemenssimatic_cn_4100_firmware< 2.52.5

Detection & IOCsextracted from sources · hover to see the quote

  • Target device is SIMATIC CN 4100 running firmware versions prior to V2.5; look for authenticated low-privilege remote access attempts that result in admin-level configuration changes on this device
  • The vulnerability is exploitable remotely with low attack complexity and only requires low privileges (CVSS: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H); monitor for unexpected privilege escalation to admin on SIMATIC CN 4100 devices
  • Focus detection on unauthorized modifications to configuration files on SIMATIC CN 4100 devices, as the attack vector involves improper access controls in those files
  • ·No known public exploits specifically target this vulnerability at time of advisory publication; exploitation evidence may be limited
  • ·All versions of SIMATIC CN 4100 prior to V2.5 are affected; patched version is V2.5 or later
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.