CVE-2025-40938: Critical severity Siemens SIMATIC CN 4100 vulnerability
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40938?
CVE-2025-40938 is considered a high-severity vulnerability due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2025-40938?
To fix CVE-2025-40938, update the SIMATIC CN 4100 device to version 4.0.1 or later.
What type of information is affected by CVE-2025-40938?
CVE-2025-40938 affects sensitive information stored in the firmware of the SIMATIC CN 4100.
Who is affected by CVE-2025-40938?
Organizations using any version of SIMATIC CN 4100 that is earlier than 4.0.1 are affected by CVE-2025-40938.
Can CVE-2025-40938 be exploited remotely?
Yes, CVE-2025-40938 can potentially be exploited remotely, allowing attackers to access sensitive information.