Junglewise Threat Intelligence

CVE-2026-22925: Siemens SIMATIC CN 4100 resource exhaustion via TCP SYN flood

CVE-2026-22925 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Siemens SIMATIC CN 4100. Vendors: Siemens.

Executive brief

The SIMATIC CN 4100 is a communication node used to integrate third-party systems into industrial process control environments. A vulnerability in this device allows a remote attacker to overwhelm its processing capabilities by sending a high volume of specific network traffic (TCP SYN packets). If exploited, this would cause the device to become unresponsive, potentially disrupting industrial operations and communication between connected systems.

Technical details

The SIMATIC CN 4100 (versions prior to V5.0) is susceptible to a resource exhaustion vulnerability (CWE-770) triggered by a TCP SYN flood attack. An unauthenticated remote attacker can exploit this by sending a high volume of TCP SYN packets to the device, exhausting system resources and rendering the communication service unavailable. This results in a denial-of-service (DoS) condition. The vulnerability is addressed in firmware version V5.0. Security engineers are advised to update affected hardware and implement network-level protections to throttle or block suspicious TCP traffic.

Affected products

  • Siemens SIMATIC CN 4100 All versions < V5.0

Timeline

  • 2026-05-12: disclosed: Initial advisory publication by Siemens
  • 2026-05-12: patched: Siemens released version V5.0 to address the issue

References

Related threats