SSH Configuration Flaw in SIMATIC CN 4100 Affects Siemens Devices
CVE-2023-29131

7.4HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 July 2023

Summary

A security weakness has been discovered in the SIMATIC CN 4100 which affects all versions prior to V2.5. This vulnerability arises from an incorrect default setting in the SSH configuration that could potentially enable unauthorized network access, allowing attackers to circumvent established network isolation protections. Such exploitation could lead to significant security risks for industrial control environments.

Affected Version(s)

SIMATIC CN 4100 All versions < V2.5

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.