cbcvebase.
CVE-2025-40593
published 2025-07-08

CVE-2025-40593: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files…

high7.1CVSS 4.0
AVNACLATNPRLUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This could allow an attacker to cause a denial of service condition.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_cn_4100< V4.0V4.0
siemenssimatic_cn_4100_firmware< 4.04.0