PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40941 Siemens CVE debrief

CVE-2025-40941 is a medium-severity information disclosure issue affecting Siemens SIMATIC CN 4100. According to the advisory, affected devices may expose server information in responses, which could help an attacker with network access profile the target and increase the likelihood of targeted attacks. Siemens provides a fix in V4.0.1 or later, and the supplied corpus does not indicate KEV listing or known active exploitation.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-09
Original CVE updated
2025-12-09
Advisory published
2025-12-09
Advisory updated
2025-12-09

Who should care

OT/ICS operators, Siemens SIMATIC CN 4100 administrators, network defenders monitoring industrial environments, and asset owners who expose this device to broader internal networks or remote management paths.

Technical summary

The issue is described as server information being exposed in device responses. CISA lists the CVSS v3.1 vector as AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (4.3), indicating network-accessible exploitation with low privileges and a confidentiality impact only. The supplier remediation in the corpus is to update to V4.0.1 or later.

Defensive priority

Moderate priority. The impact is limited to information disclosure, but the device is in an OT/ICS context where exposed server details can aid reconnaissance and follow-on targeting.

Recommended defensive actions

  • Verify whether Siemens SIMATIC CN 4100 devices are present in your environment and identify their firmware versions.
  • Apply Siemens' remediation by updating to V4.0.1 or later.
  • Restrict network access to the device to trusted management segments and minimize exposure to unnecessary internal or external hosts.
  • Review logs and management exposure for unexpected access to SIMATIC CN 4100 services.
  • Use the CISA ICS recommended practices and defense-in-depth guidance for segmentation and hardening of industrial networks.

Evidence notes

Source corpus: CISA CSAF advisory ICSA-26-015-12 and Siemens advisory SSA-416652. The advisory text states that affected devices expose server information in responses and that this could aid targeted attacks. The supplied corpus lists Siemens as vendor, SIMATIC CN 4100 as product, CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, and remediation to update to V4.0.1 or later. Enrichment in the corpus indicates no KEV entry and no known ransomware campaign use.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40941 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40941

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40941 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40941

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-12.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-416652.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-416652.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-015-12.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-12

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.