A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments.
This could allow an authenticated attacker to execute arbitrary code with limited privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow an authenticated attacker to execute arbitrary code with limited privileges. | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-12-09T10:44:35.795Z
Updated: 2025-12-09T15:33:38.168Z
Reserved: 2025-04-16T09:06:15.878Z
Link: CVE-2025-40937
Updated: 2025-12-09T15:33:30.355Z
Status : Undergoing Analysis
Published: 2025-12-09T16:17:47.260
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-40937
No data.