Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-32742
Disclosure Date: May 14, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system and gain complete read/write access to the filesystem.
0
Attacker Value
Unknown
CVE-2024-32741
Disclosure Date: May 14, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.
0
Attacker Value
Unknown
CVE-2024-32740
Disclosure Date: May 14, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device
locally or over the network.
0
Attacker Value
Unknown
CVE-2023-49621
Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.
0
Attacker Value
Unknown
CVE-2023-49252
Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of service condition.
0
Attacker Value
Unknown
CVE-2023-49251
Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take control of the device even after the affected device is fully set up.
0
Attacker Value
Unknown
CVE-2023-29131
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
0
Attacker Value
Unknown
CVE-2023-29130
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.
0