Siemens SIMATIC CN 4100 Input Validation Vulnerability in REST API Allowing Arbitrary Code Execution

Vulnerability

An input validation vulnerability has been identified in Siemens SIMATIC CN 4100, all versions prior to 4.0.1. The issue arises because the application does not properly validate input parameters in its REST API, leading to improper handling of unexpected arguments. This vulnerability could enable an authenticated attacker to execute arbitrary code with limited privileges.

Impact

Exploitation of this vulnerability could result in unauthorized execution of code, albeit with restricted privileges.

Remediation

Users are advised to update to version 4.0.1 or later. Additional information can be found on the Siemens support portal.

Added: Dec 9, 2025, 8:06 PM
Updated: Dec 9, 2025, 8:06 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
4.9
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.