CVE-2025-40938CRITICAL 9.8EPSS p23.9%

CVE-2025-40938CVE-2025-40938

Description

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.32% probability of exploitation · percentile 23.9% · 2026-06-19T12:03:05Z
Published2025-12-09
Last modified2025-12-10

Underlying weaknesses· 1

CWE-798

References

  1. https://cert-portal.siemens.com/productcert/html/ssa-416652.html

1

TypeTargetConfidenceTier
WeaknessUse of Hard-coded Credentialscwe-7980%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-40937
CVE
CVE-2026-22924
CVE
CVE-2025-40771
CVE
CVE-2025-40944
CVE
CVE-2025-40804
CVE
CVE-2025-40795
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.