cbcvebase.
CVE-2024-32741
published 2024-05-14

CVE-2024-32741: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged…

PriorityP270critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.63%
45.9th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_cn_4100< V3.0V3.0
siemenssimatic_cn_4100_firmware< 3.03.0

Detection & IOCsextracted from sources · hover to see the quote

  • Target device is SIMATIC CN 4100 (all versions prior to V3.0); detect exploitation attempts targeting the hard-coded root password or GRUB bootloader credential on this platform
  • Monitor for successful root-level authentication on SIMATIC CN 4100 devices, especially over the network (AV:N), which may indicate cracked hard-coded credential abuse
  • Alert on any remote login as 'root' to SIMATIC CN 4100 devices; the hard-coded password enables network-accessible root compromise with no privileges required
  • ·CVE-2024-32740 (hard-coded undocumented users/credentials) is a distinct but related vulnerability on the same device; detections should account for both CVEs together when monitoring SIMATIC CN 4100
  • ·CVE-2024-32742 (unrestricted USB port) on the same device allows local boot of alternate OS for full filesystem access; physical access controls are also required alongside patching
  • ·No known public exploitation has been reported at time of advisory publication
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.