cbcvebase.
CVE-2024-32740
published 2024-05-14

CVE-2024-32740: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.70%
49.1th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_cn_4100< V3.0V3.0
siemenssimatic_cn_4100_firmware< 3.03.0

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-32740 involves undocumented (hidden) user accounts with hardcoded credentials on SIMATIC CN 4100 devices (all versions < V3.0). Detect by auditing active user accounts on the device for any accounts not provisioned by the administrator.
  • Exploitation can occur remotely with no authentication and no user interaction (CVSS AV:N/AC:L/PR:N/UI:N). Monitor for unexpected remote login attempts or authenticated sessions on SIMATIC CN 4100 devices, especially from external network sources.
  • Scope detection to SIMATIC CN 4100 devices running firmware versions prior to V3.0. Inventory and fingerprint these devices on the network as a priority for patching and monitoring.
  • ·The specific undocumented usernames and credential values are not publicly disclosed in the available sources. Detection of exploitation relies on behavioral/anomaly-based monitoring rather than credential-specific signatures.
  • ·This CVE is one of three related vulnerabilities (CVE-2024-32740, CVE-2024-32741, CVE-2024-32742) affecting the same product. CVE-2024-32741 additionally covers a hardcoded root and GRUB bootloader password, and CVE-2024-32742 covers unrestricted USB boot access — all fixed in V3.0.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.