Inconsistent SNMP Behavior in SIMATIC CN 4100 by Siemens
CVE-2025-40940

6.9MEDIUM

Key Information:

Vendor

Siemens

Vendor
CVE Published:
9 December 2025

What is CVE-2025-40940?

A vulnerability exists in the SIMATIC CN 4100 where inconsistent behavior in the Simple Network Management Protocol (SNMP) may lead to unexpected service availability and unreliable configuration handling across different protocol versions. This vulnerability can expose sensitive information, creating significant risks for data confidentiality and system integrity. It is essential for users of SIMATIC CN 4100 to review their configurations and apply necessary security measures.

Affected Version(s)

SIMATIC CN 4100 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40940 : Inconsistent SNMP Behavior in SIMATIC CN 4100 by Siemens