Privilege Escalation Vulnerability in SIMATIC CN 4100 by Siemens
CVE-2023-29130

9.9CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 July 2023

Summary

A privilege escalation vulnerability has been detected in the SIMATIC CN 4100, affecting all versions prior to V2.5. This vulnerability stems from improper access controls within the configuration files, allowing attackers to elevate their privileges to admin status. As a result, an unauthorized user can gain complete control over the affected device, posing significant risks to system integrity and security. It is imperative for users to assess their systems and apply necessary mitigations to prevent exploitation.

Affected Version(s)

SIMATIC CN 4100 All versions < V2.5

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.