# CVE-2023-49621

## Summary

- **CVE ID:** CVE-2023-49621
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
- **CWE:** CWE-1392
- **Published:** Jan 9, 2024
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.

## Affected Products

- Siemens — SIMATIC CN 4100 (All versions < V2.7)

## References

- [CNA](https://cert-portal.siemens.com/productcert/pdf/ssa-777015.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 35.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._