#VU119800 Improper access control in SIMATIC CN 4100 - CVE-2025-40939
Published: December 10, 2025
SIMATIC CN 4100
Siemens
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected device contains a USB port which allows unauthenticated connections. An attacker with physical access can bypass implemented security restrictions and perform a denial of service (DoS) attack.