{"schema_version":1,"title":"Siemens SIMATIC CN 4100 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 74 vulnerabilities in Siemens SIMATIC CN 4100: 0 in the last 7 days and 0 in the last 90 days, 11 of them critical and 2 exploited in the wild. The most recent, CVE-2026-22925, was published on 12 May 2026.","url":"https://junglewise.ai/threats/technologies/simatic-cn-4100","json_url":"https://junglewise.ai/threats/technologies/simatic-cn-4100.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/simatic-cn-4100","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":40,"all_time":74,"critical":11,"exploited":2,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":17},"latest":[{"cve":"CVE-2026-22925","cvss":7.5,"epss":0.0032,"slug":"cve-2026-22925-siemens-simatic-cn-4100-resource-exhaustion-via-tcp-syn-flood","title":"Siemens SIMATIC CN 4100 resource exhaustion via TCP SYN flood","severity":"high","exploited":false,"published_at":"2026-05-12T10:16:44.057+00:00","url":"https://junglewise.ai/threats/cve-2026-22925-siemens-simatic-cn-4100-resource-exhaustion-via-tcp-syn-flood"},{"cve":"CVE-2026-22924","cvss":9.1,"epss":0.003,"slug":"cve-2026-22924-siemens-simatic-cn-4100-missing-authentication-and-resource","title":"Siemens SIMATIC CN 4100 missing authentication and resource exhaustion","severity":"critical","exploited":false,"published_at":"2026-05-12T10:16:43.917+00:00","url":"https://junglewise.ai/threats/cve-2026-22924-siemens-simatic-cn-4100-missing-authentication-and-resource"},{"cve":"CVE-2026-31431","cvss":7.8,"epss":0.0257,"slug":"cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling","title":"Linux Kernel crypto algif_aead improper memory handling","severity":"critical","exploited":true,"published_at":"2026-04-22T09:16:21.27+00:00","url":"https://junglewise.ai/threats/cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling"},{"cve":"CVE-2026-31790","cvss":7.5,"epss":0.012,"slug":"cve-2026-31790-openssl-uninitialized-memory-disclosure-in-rsasve-key","title":"OpenSSL uninitialized memory disclosure in RSASVE key encapsulation","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.77+00:00","url":"https://junglewise.ai/threats/cve-2026-31790-openssl-uninitialized-memory-disclosure-in-rsasve-key"},{"cve":"CVE-2026-31789","cvss":9.8,"epss":0.0024,"slug":"cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion","title":"OpenSSL heap buffer overflow in buf2hex conversion","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.617+00:00","url":"https://junglewise.ai/threats/cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion"},{"cve":"CVE-2026-28390","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.19+00:00","url":"https://junglewise.ai/threats/cve-2026-28390-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28389","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing","title":"OpenSSL NULL pointer dereference in CMS EnvelopedData processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:21.03+00:00","url":"https://junglewise.ai/threats/cve-2026-28389-openssl-null-pointer-dereference-in-cms-envelopeddata-processing"},{"cve":"CVE-2026-28388","cvss":7.5,"epss":0.0106,"slug":"cve-2026-28388-openssl-null-pointer-dereference-in-delta-crl-processing","title":"OpenSSL NULL pointer dereference in delta CRL processing","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.863+00:00","url":"https://junglewise.ai/threats/cve-2026-28388-openssl-null-pointer-dereference-in-delta-crl-processing"},{"cve":"CVE-2026-28387","cvss":8.1,"epss":0.008,"slug":"cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication","title":"OpenSSL use-after-free in DANE TLSA-based authentication","severity":"high","exploited":false,"published_at":"2026-04-07T22:16:20.7+00:00","url":"https://junglewise.ai/threats/cve-2026-28387-openssl-use-after-free-in-dane-tlsa-based-authentication"},{"cve":"CVE-2026-21947","cvss":3.1,"slug":"cve-2026-21947-oracle-java-se-xss-in-javafx","title":"Oracle Java SE XSS in JavaFX","severity":"low","exploited":false,"published_at":"2026-01-20T22:15:57.62+00:00","url":"https://junglewise.ai/threats/cve-2026-21947-oracle-java-se-xss-in-javafx"},{"cve":"CVE-2026-21945","cvss":7.5,"epss":0.0055,"slug":"cve-2026-21945-oracle-java-se-and-graalvm-denial-of-service-in-security","title":"Oracle Java SE and GraalVM denial of service in Security component","severity":"high","exploited":false,"published_at":"2026-01-20T22:15:57.39+00:00","url":"https://junglewise.ai/threats/cve-2026-21945-oracle-java-se-and-graalvm-denial-of-service-in-security"},{"cve":"CVE-2026-21933","cvss":6.1,"slug":"cve-2026-21933-oracle-java-se-and-graalvm-networking-data-manipulation","title":"Oracle Java SE and GraalVM networking data manipulation","severity":"medium","exploited":false,"published_at":"2026-01-20T22:15:55.917+00:00","url":"https://junglewise.ai/threats/cve-2026-21933-oracle-java-se-and-graalvm-networking-data-manipulation"},{"cve":"CVE-2026-21932","cvss":7.4,"epss":0.0025,"slug":"cve-2026-21932-oracle-java-se-improper-uri-handling-in-awt-and-javafx","title":"Oracle Java SE improper URI handling in AWT and JavaFX","severity":"high","exploited":false,"published_at":"2026-01-20T22:15:55.793+00:00","url":"https://junglewise.ai/threats/cve-2026-21932-oracle-java-se-improper-uri-handling-in-awt-and-javafx"},{"cve":"CVE-2026-21925","cvss":4.8,"slug":"cve-2026-21925-oracle-java-se-and-graalvm-data-manipulation-in-rmi","title":"Oracle Java SE and GraalVM data manipulation in RMI","severity":"medium","exploited":false,"published_at":"2026-01-20T22:15:54.917+00:00","url":"https://junglewise.ai/threats/cve-2026-21925-oracle-java-se-and-graalvm-data-manipulation-in-rmi"},{"cve":"CVE-2025-61795","cvss":5.3,"epss":0.0117,"slug":"cve-2025-61795-apache-tomcat-dos-via-delayed-cleanup-of-multipart-temporary","title":"Apache Tomcat DoS via delayed cleanup of multipart temporary files","severity":"medium","exploited":false,"published_at":"2025-10-27T18:15:44.2+00:00","url":"https://junglewise.ai/threats/cve-2025-61795-apache-tomcat-dos-via-delayed-cleanup-of-multipart-temporary"},{"cve":"CVE-2025-55752","cvss":7.5,"epss":0.6654,"slug":"cve-2025-55752-apache-tomcat-relative-path-traversal-in-url-rewrite","title":"Apache Tomcat relative path traversal in URL rewrite normalization","severity":"high","exploited":false,"published_at":"2025-10-27T18:15:42.283+00:00","url":"https://junglewise.ai/threats/cve-2025-55752-apache-tomcat-relative-path-traversal-in-url-rewrite"},{"cve":"CVE-2025-61748","cvss":3.7,"slug":"cve-2025-61748-oracle-java-se-and-graalvm-improper-access-control-in-libraries","title":"Oracle Java SE and GraalVM improper access control in Libraries","severity":"low","exploited":false,"published_at":"2025-10-21T20:20:51.057+00:00","url":"https://junglewise.ai/threats/cve-2025-61748-oracle-java-se-and-graalvm-improper-access-control-in-libraries"},{"cve":"CVE-2025-39866","cvss":7.8,"epss":0.0029,"slug":"cve-2025-39866-linux-kernel-use-after-free-in-mark-inode-dirty","title":"Linux Kernel use-after-free in __mark_inode_dirty","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:45.657+00:00","url":"https://junglewise.ai/threats/cve-2025-39866-linux-kernel-use-after-free-in-mark-inode-dirty"},{"cve":"CVE-2025-39857","cvss":7.5,"epss":0.0014,"slug":"cve-2025-39857-linux-kernel-null-pointer-dereference-in-net-smc","title":"Linux Kernel NULL pointer dereference in net/smc","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:44.65+00:00","url":"https://junglewise.ai/threats/cve-2025-39857-linux-kernel-null-pointer-dereference-in-net-smc"},{"cve":"CVE-2025-39849","cvss":8.8,"epss":0.0014,"slug":"cve-2025-39849-linux-kernel-out-of-bounds-write-in-cfg80211-sme-ssid-handling","title":"Linux Kernel out-of-bounds write in cfg80211 SME SSID handling","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:43.76+00:00","url":"https://junglewise.ai/threats/cve-2025-39849-linux-kernel-out-of-bounds-write-in-cfg80211-sme-ssid-handling"},{"cve":"CVE-2025-39848","cvss":8.8,"epss":0.0015,"slug":"cve-2025-39848-linux-kernel-memory-corruption-in-ax25-kiss-rcv","title":"Linux Kernel memory corruption in ax25_kiss_rcv","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:43.64+00:00","url":"https://junglewise.ai/threats/cve-2025-39848-linux-kernel-memory-corruption-in-ax25-kiss-rcv"},{"cve":"CVE-2025-39845","cvss":5.5,"epss":0.0014,"slug":"cve-2025-39845-linux-kernel-x86-64-page-table-synchronization-failure","title":"Linux Kernel x86_64 page table synchronization failure","severity":"medium","exploited":false,"published_at":"2025-09-19T16:15:43.28+00:00","url":"https://junglewise.ai/threats/cve-2025-39845-linux-kernel-x86-64-page-table-synchronization-failure"},{"cve":"CVE-2025-39827","cvss":5.5,"epss":0.0013,"slug":"cve-2025-39827-linux-kernel-slab-use-after-free-in-rose-network-protocol","title":"Linux Kernel slab-use-after-free in ROSE network protocol","severity":"medium","exploited":false,"published_at":"2025-09-16T13:16:02.873+00:00","url":"https://junglewise.ai/threats/cve-2025-39827-linux-kernel-slab-use-after-free-in-rose-network-protocol"},{"cve":"CVE-2025-39826","cvss":7,"epss":0.0013,"slug":"cve-2025-39826-linux-kernel-use-after-free-in-rose-networking-protocol","title":"Linux Kernel use-after-free in ROSE networking protocol","severity":"high","exploited":false,"published_at":"2025-09-16T13:16:02.29+00:00","url":"https://junglewise.ai/threats/cve-2025-39826-linux-kernel-use-after-free-in-rose-networking-protocol"},{"cve":"CVE-2025-39825","cvss":7.8,"epss":0.001,"slug":"cve-2025-39825-linux-kernel-smb-client-race-condition-in-rename-operation","title":"Linux Kernel SMB client race condition in rename operation","severity":"high","exploited":false,"published_at":"2025-09-16T13:16:01.78+00:00","url":"https://junglewise.ai/threats/cve-2025-39825-linux-kernel-smb-client-race-condition-in-rename-operation"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":204,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},{"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens RUGGEDCOM APE1808","slug":"ruggedcom-ape1808","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/ruggedcom-ape1808"},{"name":"Siemens RUGGEDCOM RST2428P","slug":"ruggedcom-rst2428p","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p"},{"name":"Siemens ROX II","slug":"rox-ii","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rox-ii"},{"name":"Siemens SINEC OS","slug":"sinec-os","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/sinec-os"},{"name":"Siemens Solid Edge","slug":"solid-edge","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/solid-edge"},{"name":"Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem","slug":"simatic-s7-1500-tm-mfp-gnu-linux-subsystem","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem"},{"name":"Siemens Ruggedcom Rox II","slug":"ruggedcom-rox-ii","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rox-ii"},{"name":"Siemens Reyrolle 7SR5","slug":"reyrolle-7sr5","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/reyrolle-7sr5"},{"name":"Siemens Simcenter Femap","slug":"simcenter-femap","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/simcenter-femap"}],"technology":{"hub":true,"name":"Siemens SIMATIC CN 4100","slug":"simatic-cn-4100","vendor":{"name":"Siemens","slug":"siemens","url":"https://junglewise.ai/threats/vendors/siemens"},"aliases":[],"category":"firmware","url":"https://junglewise.ai/threats/technologies/simatic-cn-4100"},"most_severe":[{"cve":"CVE-2025-39682","cvss":9.8,"epss":0.0288,"slug":"cve-2025-39682-linux-kernel-memory-corruption-in-tls-zero-length-record-handling","title":"Linux Kernel memory corruption in TLS zero-length record handling","severity":"critical","exploited":true,"published_at":"2025-09-05T18:15:44.67+00:00","url":"https://junglewise.ai/threats/cve-2025-39682-linux-kernel-memory-corruption-in-tls-zero-length-record-handling"},{"cve":"CVE-2026-31431","cvss":7.8,"epss":0.0257,"slug":"cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling","title":"Linux Kernel crypto algif_aead improper memory handling","severity":"critical","exploited":true,"published_at":"2026-04-22T09:16:21.27+00:00","url":"https://junglewise.ai/threats/cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling"},{"cve":"CVE-2026-31789","cvss":9.8,"epss":0.0024,"slug":"cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion","title":"OpenSSL heap buffer overflow in buf2hex conversion","severity":"critical","exploited":false,"published_at":"2026-04-07T22:16:21.617+00:00","url":"https://junglewise.ai/threats/cve-2026-31789-openssl-heap-buffer-overflow-in-buf2hex-conversion"},{"cve":"CVE-2025-38724","cvss":9.8,"epss":0.0016,"slug":"cve-2025-38724-linux-kernel-nfsd-use-after-free-in-nfsd4-setclientid-confirm","title":"Linux Kernel nfsd use-after-free in nfsd4_setclientid_confirm","severity":"critical","exploited":false,"published_at":"2025-09-04T16:15:42.273+00:00","url":"https://junglewise.ai/threats/cve-2025-38724-linux-kernel-nfsd-use-after-free-in-nfsd4-setclientid-confirm"},{"cve":"CVE-2025-38708","cvss":9.8,"epss":0.0016,"slug":"cve-2025-38708-linux-kernel-use-after-free-in-drbd-handle-write-conflicts","title":"Linux Kernel use after free in DRBD handle_write_conflicts","severity":"critical","exploited":false,"published_at":"2025-09-04T16:15:39.847+00:00","url":"https://junglewise.ai/threats/cve-2025-38708-linux-kernel-use-after-free-in-drbd-handle-write-conflicts"},{"cve":"CVE-2025-39703","cvss":9.8,"epss":0.0015,"slug":"cve-2025-39703-linux-kernel-denial-of-service-in-hsr-frame-processing","title":"Linux kernel denial of service in HSR frame processing","severity":"critical","exploited":false,"published_at":"2025-09-05T18:15:47.417+00:00","url":"https://junglewise.ai/threats/cve-2025-39703-linux-kernel-denial-of-service-in-hsr-frame-processing"},{"cve":"CVE-2025-39702","cvss":9.8,"epss":0.0015,"slug":"cve-2025-39702-linux-kernel-timing-attack-in-ipv6-segment-routing-hmac","title":"Linux Kernel timing attack in IPv6 Segment Routing HMAC validation","severity":"critical","exploited":false,"published_at":"2025-09-05T18:15:47.27+00:00","url":"https://junglewise.ai/threats/cve-2025-39702-linux-kernel-timing-attack-in-ipv6-segment-routing-hmac"},{"cve":"CVE-2025-39673","cvss":9.8,"epss":0.001,"slug":"cve-2025-39673-linux-kernel-race-condition-in-ppp-fill-forward-path","title":"Linux Kernel race condition in ppp_fill_forward_path","severity":"critical","exploited":false,"published_at":"2025-09-05T18:15:43.23+00:00","url":"https://junglewise.ai/threats/cve-2025-39673-linux-kernel-race-condition-in-ppp-fill-forward-path"},{"cve":"CVE-2025-38552","cvss":9.4,"epss":0.0016,"slug":"cve-2025-38552-linux-kernel-race-condition-in-mptcp-subflow-creation","title":"Linux Kernel race condition in MPTCP subflow creation","severity":"critical","exploited":false,"published_at":"2025-08-16T12:15:31.4+00:00","url":"https://junglewise.ai/threats/cve-2025-38552-linux-kernel-race-condition-in-mptcp-subflow-creation"},{"cve":"CVE-2026-22924","cvss":9.1,"epss":0.003,"slug":"cve-2026-22924-siemens-simatic-cn-4100-missing-authentication-and-resource","title":"Siemens SIMATIC CN 4100 missing authentication and resource exhaustion","severity":"critical","exploited":false,"published_at":"2026-05-12T10:16:43.917+00:00","url":"https://junglewise.ai/threats/cve-2026-22924-siemens-simatic-cn-4100-missing-authentication-and-resource"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}