CVE-2023-29131: Critical severity Siemens SIMATIC CN 4100 vulnerability
Published Jul 11, 2023
·Updated
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
Affected Software
2 affected components
Siemens SIMATIC CN 4100<2.5
Siemens Simatic Cn 4100 Firmware<2.5
Remediation
Event History
Jul 11, 2023
CVE Published
via MITRE·09:07 AM
Data Sourced
via MITRE·09:07 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-29131?
CVE-2023-29131 has been rated as a medium severity vulnerability due to potential network isolation bypass.
2
How do I fix CVE-2023-29131?
To remediate CVE-2023-29131, update the SIMATIC CN 4100 to version 2.5 or later to correct the default SSH configuration.
3
What systems are affected by CVE-2023-29131?
CVE-2023-29131 affects all versions of SIMATIC CN 4100 prior to 2.5.
4
Can CVE-2023-29131 be exploited remotely?
Yes, an attacker can potentially exploit CVE-2023-29131 remotely by bypassing network isolation.
5
What does the default value in the SSH configuration mean for CVE-2023-29131?
The incorrect default value in the SSH configuration allows unauthorized access, making the device vulnerable to exploitation.