CVE-2023-29131: Siemens SIMATIC Cn 4100 Firmware

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.

Affected products

  • Siemens SIMATIC Cn 4100 Firmware: before 2.5 (fixed in 2.5)

Published 2023-07-11. Last modified 2026-06-17.