CVE-2025-40939: Medium severity Siemens SIMATIC CN 4100 vulnerability
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that could cause denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40939?
CVE-2025-40939 has a high severity rating due to the potential for denial of service via unauthenticated physical access.
How do I fix CVE-2025-40939?
To mitigate CVE-2025-40939, upgrade the SIMATIC CN 4100 to version 4.0.1 or higher.
What is affected by CVE-2025-40939?
CVE-2025-40939 affects all versions of the Siemens SIMATIC CN 4100 that are below version 4.0.1.
What type of access is required to exploit CVE-2025-40939?
Exploitation of CVE-2025-40939 requires physical access to the affected device's USB port.
What is the impact of CVE-2025-40939?
The impact of CVE-2025-40939 can lead to a denial of service condition through unauthorized rebooting of the device.