CVE-2025-40941: Infoleak
Published Dec 9, 2025
·Updated
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood of targeted attacks.
Affected Software
3 affected components
Siemens SIMATIC CN 4100<4.0.1
All of the following
Siemens Simatic Cn 4100 Firmware<4.0.1
Siemens SIMATIC CN 4100
Event History
Dec 9, 2025
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40941?
CVE-2025-40941 is considered a moderate severity vulnerability that exposes server information.
2
How do I fix CVE-2025-40941?
To mitigate CVE-2025-40941, upgrade SIMATIC CN 4100 to version 4.0.1 or later.
3
What devices are affected by CVE-2025-40941?
CVE-2025-40941 affects all versions of SIMATIC CN 4100 that are earlier than version 4.0.1.
4
What are the risks associated with CVE-2025-40941?
The risks of CVE-2025-40941 include potential targeted attacks due to exposed server information.
5
How does CVE-2025-40941 allow attackers access?
CVE-2025-40941 allows attackers with network access to gain sensitive server information, increasing attack vectors.