CVE-2025-40593: Input Validation
Published Jul 8, 2025
·Updated
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This could allow an attacker to cause a denial of service condition.
Affected Software
3 affected components
Siemens SIMATIC CN 4100<4.0
All of the following
Siemens Simatic Cn 4100 Firmware<4.0
Siemens SIMATIC CN 4100
Event History
Jul 8, 2025
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40593?
CVE-2025-40593 is considered a medium severity vulnerability due to its potential to cause a denial of service condition.
2
How do I fix CVE-2025-40593?
To mitigate CVE-2025-40593, upgrade to SIMATIC CN 4100 version 4.0 or later.
3
What devices are affected by CVE-2025-40593?
CVE-2025-40593 affects all versions of the SIMATIC CN 4100 prior to version 4.0.
4
What type of attack does CVE-2025-40593 enable?
CVE-2025-40593 enables an attacker to control the device by storing arbitrary files in its SFTP folder.
5
Is there any workaround for CVE-2025-40593?
Currently, there are no established workarounds for CVE-2025-40593 other than upgrading.