CVE-2025-40938High· 8.1▾ TwilightA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.
simatic_cn_4100_firmware < 4.0.1Upgrade past the affected range:
simatic_cn_4100_firmware 4.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-40939Medium· 4.6A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40940Medium· 4.9A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40941Medium· 4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40937High· 8.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2019-6693Medium· 6.5Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key
CVE-2024-23687Critical· 9.1Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…