CVE-2024-32741: Siemens SIMATIC Cn 4100 Firmware

Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.

Affected products

  • Siemens SIMATIC Cn 4100 Firmware: before 3.0 (fixed in 3.0)

Published 2024-05-14. Last modified 2026-06-17.