CVE-2025-40937

8.3

Siemens · SIMATIC CN 4100

A command injection vulnerability in the Siemens SIMATIC CN 4100 REST API allows authenticated attackers to execute arbitrary code due to improper input validation.

Executive summary

A command injection vulnerability in the Siemens SIMATIC CN 4100 REST API poses a significant risk to operational integrity by allowing authenticated attackers to execute arbitrary code.

Vulnerability

The vulnerability is a command injection flaw (CWE-77) originating from improper validation of input parameters within the REST API, which can be triggered by any authenticated attacker with limited privileges.

Business impact

The ability to execute arbitrary code on critical industrial communication infrastructure can lead to unauthorized control over device operations or the disruption of industrial processes. Given the high CVSS score of 8.3, this flaw represents a significant threat to system availability and security, potentially resulting in operational downtime or the compromise of sensitive industrial control data.

Remediation

Immediate Action: Update the Siemens SIMATIC CN 4100 firmware to version V4.0.1 or later to address the vulnerable REST API input handling.

Proactive Monitoring: Monitor network traffic for anomalous REST API calls and review system access logs for unauthorized or suspicious command executions.

Compensating Controls: Restrict access to the management interface to trusted, authenticated users only and implement network segmentation to isolate the SIMATIC CN 4100 from unauthorized network segments.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

This vulnerability presents a severe risk to the Siemens SIMATIC CN 4100 platform due to the potential for arbitrary command execution. Administrators should prioritize the deployment of the V4.0.1 firmware update immediately to eliminate the underlying injection vector and ensure the ongoing security of the industrial control environment.

More Siemens CVEs

Sources