A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take control of the device even after the affected device is fully set up.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: siemens

Published: 2024-01-09T10:00:08.834Z

Updated: 2024-01-09T10:00:08.834Z

Reserved: 2023-11-24T11:41:23.260Z


Link: CVE-2023-49251

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-09T10:15:19.910

Modified: 2024-01-12T15:37:49.740


Link: CVE-2023-49251

JSON object: View

cve-icon Redhat Information

No data.

CWE