CVE-2023-49621

CRITICAL

SIMATIC CN 4100 <V2.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.

Scores

CVSS v3 9.8
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (1)
siemens/simatic_cn_4100_firmware < 2.7
Published Jan 09, 2024
Tracked Since Feb 18, 2026