CVE-2025-40939

Severity
5.1MEDIUM
EPSS
0.1%
top 81.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that could cause denial of service condition.

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-40939: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V42025-12-09
GHSA
GHSA-35wm-hq5r-2p36: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V42025-12-09