Remote Access Vulnerability in SIMATIC CN 4100 by Siemens
CVE-2023-49251
9.8CRITICAL
Summary
A vulnerability exists in the SIMATIC CN 4100 system that can be exploited during the 'intermediate installation' state. This flaw allows unauthorized attackers to inject their own login credentials into the device. As a result, an attacker can obtain root-level access remotely, enabling them to assume complete control of the system, potentially leading to unauthorized configurations, data breaches, and compromise of operational integrity even after the system is fully set up.
Affected Version(s)
SIMATIC CN 4100 All versions < V2.7
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved