CVE-2026-22925: High severity Siemens SIMATIC CN 4100 vulnerability
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the service unavailable and cause denial-of-service conditions by overwhelming system resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SIMATIC CN 4100to a version that resolves this vulnerability.Fixed in V5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22925?
CVE-2026-22925 is rated as a high severity vulnerability due to its potential to cause denial-of-service conditions.
How do I fix CVE-2026-22925?
To fix CVE-2026-22925, it is recommended to upgrade to SIMATIC CN 4100 version 5.0 or higher.
What type of attack does CVE-2026-22925 involve?
CVE-2026-22925 involves a denial-of-service attack through resource exhaustion caused by high volumes of TCP SYN packets.
Which versions of SIMATIC CN 4100 are affected by CVE-2026-22925?
All versions of SIMATIC CN 4100 prior to V5.0 are affected by CVE-2026-22925.
Can CVE-2026-22925 be exploited remotely?
Yes, CVE-2026-22925 can be exploited remotely by sending a large number of TCP SYN packets.