cbcvebase.
CVE-2023-49621
published 2024-01-09

CVE-2023-49621: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.60%
44.4th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_cn_4100
siemenssimatic_cn_4100_firmware< 2.72.7

Detection & IOCsextracted from sources · hover to see the quote

  • Target the 'intermediate installation' system state of SIMATIC CN 4100 (versions prior to V2.7); exploitation involves use of default credentials with admin privileges over the network with no authentication required (CVSS PR:N)
  • CVE-2023-49621 is remotely exploitable with no privileges required and no user interaction; monitor for unauthenticated remote login attempts to SIMATIC CN 4100 devices, especially during or after initial device setup ('intermediate installation' state)
  • Successful exploitation may result in an attacker gaining complete (root-level) control of the device; correlate with CVE-2023-49251 (auth bypass allowing attacker to add own credentials as root) and CVE-2023-49252 (unauthenticated IP config change causing DoS) for broader campaign detection on SIMATIC CN 4100
  • ·The default credentials are only present during the 'intermediate installation' system state; devices that have completed full setup may still be vulnerable if the state is re-entered or if credentials were not changed
  • ·All SIMATIC CN 4100 versions prior to V2.7 are affected; the fix is to update to V2.7 or later
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.