CVE-2023-29130
published 2023-07-11CVE-2023-29130: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files…
PriorityP263critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.56%
42.9th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_cn_4100 | — | — |
| siemens | simatic_cn_4100_firmware | < 2.5 | 2.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target device is SIMATIC CN 4100 running firmware versions prior to V2.5; look for authenticated low-privilege remote access attempts that result in admin-level configuration changes on this device ↗
- →The vulnerability is exploitable remotely with low attack complexity and only requires low privileges (CVSS: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H); monitor for unexpected privilege escalation to admin on SIMATIC CN 4100 devices ↗
- →Focus detection on unauthorized modifications to configuration files on SIMATIC CN 4100 devices, as the attack vector involves improper access controls in those files ↗
- ·No known public exploits specifically target this vulnerability at time of advisory publication; exploitation evidence may be limited ↗
- ·All versions of SIMATIC CN 4100 prior to V2.5 are affected; patched version is V2.5 or later ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hqc9-64cv-8vvf: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2
ghsa_unreviewed·2023-07-11
CVE-2023-29130 [CRITICAL] CWE-284 GHSA-hqc9-64cv-8vvf: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.
CISA ICS
Siemens SIMATIC CN 4100
cisa_ics·2023-07-13·CVSS 9.9
[CRITICAL] Siemens SIMATIC CN 4100
ICS Advisory
##
Siemens SIMATIC CN 4100
Release DateJuly 13, 2023
Alert CodeICSA-23-194-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC CN 4100
- Vulnerabilities: Improper Access Control, Incorrect Default Permissions
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to gain privilege escalation and bypass network isolation.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens SIMATIC CN 4100, a communication node, are affected:
- SIMATIC CN 4100: all versions prior to V2.5
## 3.2 VULNERABILITY OVERVIEW
3.2.1 IMPROPER ACCESS CONTROL CWE-284
Affected device consists of improper access contro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published