cbcvebase.
CVE-2023-29131
published 2023-07-11

CVE-2023-29131: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration…

PriorityP264critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.42%
34.3th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_cn_4100
siemenssimatic_cn_4100_firmware< 2.52.5

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-29131 involves an incorrect default value in the SSH configuration of SIMATIC CN 4100 (all versions prior to V2.5) that could allow an attacker to bypass network isolation; monitor for unexpected SSH connections originating from or targeting SIMATIC CN 4100 devices, especially across network segment boundaries.
  • The vulnerability is exploitable remotely with low attack complexity and low privileges required (CVSS AV:N/AC:L/PR:L); alert on any low-privileged remote SSH sessions to SIMATIC CN 4100 devices that traverse network isolation boundaries.
  • Scope is changed (S:C in CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L), indicating exploitation can impact resources beyond the vulnerable component; monitor for lateral movement or cross-segment traffic originating from SIMATIC CN 4100 devices after SSH authentication events.
  • ·The vulnerability is rooted in an incorrect default SSH configuration value on the device; the misconfiguration is present in all SIMATIC CN 4100 versions prior to V2.5 and is not exploitable post-patch.
  • ·No known public exploits specifically target this vulnerability as of the advisory date (July 13, 2023); detection efforts should focus on anomalous SSH behavior rather than known exploit signatures.
  • ·The fix is a firmware update to V2.5 or later; devices running any version prior to V2.5 should be considered misconfigured by default with respect to SSH isolation.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.