CVE-2023-29130 PUBLISHED CVSS 10 CRITICAL

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.

EPSS 0.20% · 41.4th percentile

Risk Scores

CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.20%
41.4th percentile

Affected Products

VendorProductVersions
siemenssimatic_cn_4100_firmware0, 0, 0
SiemensSIMATIC CN 4100*

Timeline

References

Open in Interactive Console →