Executive brief
Siemens SIMATIC CN 4100, a communication hardware device used in industrial automation, is affected by numerous vulnerabilities that could allow an attacker to disrupt operations, steal sensitive data, or gain unauthorized control. These issues stem from underlying software components, including the Linux kernel and various system libraries. Exploitation could lead to significant service outages or the compromise of industrial control processes. Siemens has released a firmware update to address these risks.
Technical details
Siemens SIMATIC CN 4100 versions prior to V5.0 are affected by a large volume of vulnerabilities (over 100 CVEs) inherited from integrated components such as the Linux kernel, libxml2, and GLib. The vulnerability classes include memory safety issues (Use-After-Free, Stack-based Buffer Overflow, Out-of-bounds Write), improper input validation, and resource management flaws. Attack vectors range from local privilege escalation via kernel flaws to remote denial-of-service or code execution through network-facing libraries. The most severe issues allow for unauthenticated remote attacks with high impact on system availability and integrity. Siemens recommends upgrading to version V5.0 or later to remediate these vulnerabilities.
Affected products
- Siemens SIMATIC CN 4100 < 5.0
CVE identifiers
- CVE-2025-39743
- CVE-2025-39715
- CVE-2025-38724
- CVE-2025-38706
- CVE-2025-39788
- CVE-2025-39714
- CVE-2025-39684
- CVE-2025-38723
- CVE-2025-39676
- CVE-2025-39806
- CVE-2025-8916
- CVE-2025-39795
- CVE-2025-39719
- CVE-2025-38614
- CVE-2025-38681
- CVE-2025-39687
- CVE-2026-28389
- CVE-2025-39828
- CVE-2025-55752
- CVE-2025-38491
- CVE-2025-39838
- CVE-2025-53057
- CVE-2025-38687
- CVE-2025-39757
- CVE-2025-39736
- CVE-2025-6021
- CVE-2025-39694
- CVE-2025-39749
- CVE-2026-2673
- CVE-2025-55754
- CVE-2025-39812
- CVE-2025-38701
- CVE-2025-39703
- CVE-2025-38697
- CVE-2025-38676
- CVE-2025-39826
- CVE-2025-38728
- CVE-2025-9232
- CVE-2025-38727
- CVE-2025-9820
- CVE-2025-38685
- CVE-2025-39827
- CVE-2025-39801
- CVE-2025-39819
- CVE-2025-39683
- CVE-2025-39709
- CVE-2025-38698
- CVE-2026-21932
- CVE-2025-39716
- CVE-2025-43368
- CVE-2025-39825
- CVE-2025-38670
- CVE-2025-39843
- CVE-2025-39738
- CVE-2025-39691
- CVE-2025-38711
- CVE-2025-39756
- CVE-2025-38708
- CVE-2026-21933
- CVE-2025-39864
- CVE-2025-39846
- CVE-2025-39798
- CVE-2025-48989
- CVE-2025-38684
- CVE-2025-39782
- CVE-2025-38736
- CVE-2025-39847
- CVE-2025-39808
- CVE-2025-38702
- CVE-2025-38715
- CVE-2025-39857
- CVE-2025-39844
- CVE-2025-38502
- CVE-2025-14831
- CVE-2025-39841
- CVE-2025-61748
- CVE-2025-39772
- CVE-2026-31790
- CVE-2025-39759
- CVE-2025-39813
- CVE-2026-22925
- CVE-2024-58240
- CVE-2025-38679
- CVE-2025-39773
- CVE-2025-38347
- CVE-2026-28390
- CVE-2025-39866
- CVE-2025-38714
- CVE-2025-39787
- CVE-2025-39689
- CVE-2025-37968
- CVE-2025-38713
- CVE-2025-38695
- CVE-2025-39673
- CVE-2025-23160
- CVE-2025-38735
- CVE-2025-39701
- CVE-2025-38725
- CVE-2025-39692
- CVE-2024-47704
- CVE-2025-38552
- CVE-2025-47219
- CVE-2025-39790
- CVE-2025-39685
- CVE-2025-39824
- CVE-2025-39752
- CVE-2025-38729
- CVE-2026-28387
- CVE-2025-39835
- CVE-2025-38696
- CVE-2025-9230
- CVE-2025-39710
- CVE-2025-39702
- CVE-2025-39693
- CVE-2025-39776
- CVE-2025-9231
- CVE-2025-39697
- CVE-2025-39849
- CVE-2025-38707
- CVE-2025-53066
- CVE-2025-39845
- CVE-2025-39823
- CVE-2025-61795
- CVE-2025-39794
- CVE-2025-38694
- CVE-2026-22924
- CVE-2025-39766
- CVE-2025-39706
- CVE-2025-39724
- CVE-2026-21945
- CVE-2025-39783
- CVE-2025-39675
- CVE-2025-39760
- CVE-2025-40300
- CVE-2025-39713
- CVE-2025-38699
- CVE-2025-38680
- CVE-2025-39865
- CVE-2025-38683
- CVE-2025-39686
- CVE-2026-21925
- CVE-2024-57924
- CVE-2025-38693
- CVE-2026-31789
- CVE-2025-39842
- CVE-2025-6052
- CVE-2025-39853
- CVE-2025-39817
- CVE-2025-39682
- CVE-2025-39800
- CVE-2025-38732
- CVE-2025-38712
- CVE-2025-38721
- CVE-2025-38700
- CVE-2026-28388
- CVE-2025-39860
- CVE-2025-39737
- CVE-2025-31257
- CVE-2025-37931
- CVE-2025-39770
- CVE-2025-38691
- CVE-2025-7425
- CVE-2025-39718
- CVE-2025-23143
- CVE-2025-39848
- CVE-2025-38322
- CVE-2025-39839
- CVE-2026-21947
- CVE-2025-39742
- CVE-2025-39681
- CVE-2025-38677
Timeline
- 2026-05-14: advisory: CISA and Siemens published the advisory.
- 2026-05-14: patched: Siemens released version V5.0 to address the vulnerabilities.