PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-22925 Siemens CVE debrief

CVE-2026-22925 describes a network-based denial-of-service condition in Siemens SIMATIC CN 4100 versions before 5.0. According to the CISA-republished Siemens advisory, high volumes of TCP SYN packets can exhaust system resources and render the service unavailable. The safest response is to update to V5.0 or later and apply layered OT network protections while the fix is deployed.

Vendor
Siemens
Product
SIMATIC CN 4100
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

OT/ICS operators, Siemens SIMATIC CN 4100 owners, plant network administrators, and defenders responsible for availability of industrial communications services.

Technical summary

The advisory states that the affected application is susceptible to resource exhaustion when subjected to a high volume of TCP SYN packets. The vulnerability is network reachable and requires no privileges or user interaction, with an availability impact only (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The source remediation is to update to V5.0 or later. Because the issue is a resource exhaustion/denial-of-service condition, compensating controls that reduce exposure to unsolicited network traffic are relevant until remediation is complete.

Defensive priority

High. The CVSS score is 7.5 and the impact is service availability loss in an industrial context, where downtime can affect operations. Prioritize patching or upgrading affected devices and deploy network protections promptly if immediate remediation is not possible.

Recommended defensive actions

  • Update Siemens SIMATIC CN 4100 to V5.0 or later, per the vendor remediation.
  • Restrict exposure of the affected service to trusted management and control networks only.
  • Use firewalling or segmentation to limit unsolicited TCP SYN traffic toward the device.
  • Monitor for abnormal SYN rates or connection-setup spikes on affected network paths.
  • Apply CISA and vendor recommended ICS defense-in-depth practices while remediation is pending.

Evidence notes

This debrief is based on the CISA CSAF republishing of Siemens ProductCERT advisory SSA-032379, published 2026-05-12 and republished 2026-05-14. The advisory metadata names the product as Siemens SIMATIC CN 4100 and the vulnerability description as TCP SYN-driven resource exhaustion leading to denial of service. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The only documented remediation in the supplied corpus is to update to version 5.0 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-22925 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-22925

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-22925 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22925

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.