---
id: CVE-2025-40940
title: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
summary: >-
  A vulnerability has been identified in SIMATIC CN 4100 (All versions <
  V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as
  unexpected service availability and unreliable configuration handling across
  protocol v…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: siemens
product: simatic_cn_4100_firmware
affected:
  - simatic_cn_4100_firmware < 4.0.1
patched:
  - simatic_cn_4100_firmware 4.0.1
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40940'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-416652.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00366
epssPercentile: 0.28289
ingestedAt: '2026-10-07T20:46:46.792Z'
---

## Overview

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling across protocol versions. This could allow an attacker to access sensitive data, potentially leading to a breach of confidentiality.

## Affected

- `simatic_cn_4100_firmware < 4.0.1`

## Remediation

Upgrade past the affected range:

- `simatic_cn_4100_firmware 4.0.1`
