CVE-2025-40940: Infoleak
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling across protocol versions. This could allow an attacker to access sensitive data, potentially leading to a breach of confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40940?
CVE-2025-40940 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2025-40940?
To mitigate CVE-2025-40940, upgrade the SIMATIC CN 4100 software to version 4.0.1 or later.
What impact does CVE-2025-40940 have on affected systems?
CVE-2025-40940 can lead to inconsistent SNMP behavior, including unreliable configuration handling and unexpected service availability.
Who is affected by CVE-2025-40940?
All users of the Siemens SIMATIC CN 4100 software versions prior to 4.0.1 are affected by CVE-2025-40940.
Can CVE-2025-40940 be exploited remotely?
Yes, CVE-2025-40940 can potentially be exploited remotely, allowing attackers to access sensitive data.