CVE-2023-29131
published 2023-07-11CVE-2023-29131: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration…
PriorityP264critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.42%
34.3th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_cn_4100 | — | — |
| siemens | simatic_cn_4100_firmware | < 2.5 | 2.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-29131 involves an incorrect default value in the SSH configuration of SIMATIC CN 4100 (all versions prior to V2.5) that could allow an attacker to bypass network isolation; monitor for unexpected SSH connections originating from or targeting SIMATIC CN 4100 devices, especially across network segment boundaries. ↗
- →The vulnerability is exploitable remotely with low attack complexity and low privileges required (CVSS AV:N/AC:L/PR:L); alert on any low-privileged remote SSH sessions to SIMATIC CN 4100 devices that traverse network isolation boundaries. ↗
- →Scope is changed (S:C in CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L), indicating exploitation can impact resources beyond the vulnerable component; monitor for lateral movement or cross-segment traffic originating from SIMATIC CN 4100 devices after SSH authentication events. ↗
- ·The vulnerability is rooted in an incorrect default SSH configuration value on the device; the misconfiguration is present in all SIMATIC CN 4100 versions prior to V2.5 and is not exploitable post-patch. ↗
- ·No known public exploits specifically target this vulnerability as of the advisory date (July 13, 2023); detection efforts should focus on anomalous SSH behavior rather than known exploit signatures. ↗
- ·The fix is a firmware update to V2.5 or later; devices running any version prior to V2.5 should be considered misconfigured by default with respect to SSH isolation. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3q3j-5m7x-chq6: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2
ghsa_unreviewed·2023-07-11
CVE-2023-29131 [CRITICAL] CWE-276 GHSA-3q3j-5m7x-chq6: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
CISA ICS
Siemens SIMATIC CN 4100
cisa_ics·2023-07-13·CVSS 9.9
[CRITICAL] Siemens SIMATIC CN 4100
ICS Advisory
##
Siemens SIMATIC CN 4100
Release DateJuly 13, 2023
Alert CodeICSA-23-194-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC CN 4100
- Vulnerabilities: Improper Access Control, Incorrect Default Permissions
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to gain privilege escalation and bypass network isolation.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens SIMATIC CN 4100, a communication node, are affected:
- SIMATIC CN 4100: all versions prior to V2.5
## 3.2 VULNERABILITY OVERVIEW
3.2.1 IMPROPER ACCESS CONTROL CWE-284
Affected device consists of improper access contro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published