Junglewise Threat Intelligence

CVE-2026-22924: Siemens SIMATIC CN 4100 missing authentication and resource exhaustion

CVE-2026-22924 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Technologies: Siemens SIMATIC CN 4100. Vendors: Siemens.

Executive brief

The SIMATIC CN 4100 is a communication node used to connect third-party systems within industrial process control environments. A vulnerability in this device allows unauthenticated users to create excessive connections, leading to a system crash or resource exhaustion. This can disrupt industrial operations, impact system availability, and potentially allow for unauthorized actions that compromise the integrity of the control network.

Technical details

The SIMATIC CN 4100 (versions prior to V5.0) suffers from a missing authentication vulnerability (CWE-306) for critical functions. The application fails to properly restrict unauthenticated connections, making it susceptible to resource exhaustion conditions. A remote, unauthenticated attacker can exploit this by initiating a high volume of connections or specific requests to exhaust system resources, leading to a denial of service (DoS) or the ability to perform unauthorized actions. This impacts both the availability and integrity of the device. Siemens has addressed this in version V5.0.

Affected products

  • Siemens SIMATIC CN 4100 All versions < V5.0

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched: Fixed in V5.0

References

Related threats