CVE-2025-40941: Siemens SIMATIC Cn 4100 Firmware
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood of targeted attacks.
Affected products
- Siemens SIMATIC Cn 4100 Firmware: before 4.0.1 (fixed in 4.0.1)
Published 2025-12-09. Last modified 2026-10-07.