PatchSiren cyber security CVE debrief
CVE-2026-22925 Siemens CVE debrief
CVE-2026-22925 describes a network-based denial-of-service condition in Siemens SIMATIC CN 4100 versions before 5.0. According to the CISA-republished Siemens advisory, high volumes of TCP SYN packets can exhaust system resources and render the service unavailable. The safest response is to update to V5.0 or later and apply layered OT network protections while the fix is deployed.
- Vendor
- Siemens
- Product
- SIMATIC CN 4100
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
OT/ICS operators, Siemens SIMATIC CN 4100 owners, plant network administrators, and defenders responsible for availability of industrial communications services.
Technical summary
The advisory states that the affected application is susceptible to resource exhaustion when subjected to a high volume of TCP SYN packets. The vulnerability is network reachable and requires no privileges or user interaction, with an availability impact only (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The source remediation is to update to V5.0 or later. Because the issue is a resource exhaustion/denial-of-service condition, compensating controls that reduce exposure to unsolicited network traffic are relevant until remediation is complete.
Defensive priority
High. The CVSS score is 7.5 and the impact is service availability loss in an industrial context, where downtime can affect operations. Prioritize patching or upgrading affected devices and deploy network protections promptly if immediate remediation is not possible.
Recommended defensive actions
- Update Siemens SIMATIC CN 4100 to V5.0 or later, per the vendor remediation.
- Restrict exposure of the affected service to trusted management and control networks only.
- Use firewalling or segmentation to limit unsolicited TCP SYN traffic toward the device.
- Monitor for abnormal SYN rates or connection-setup spikes on affected network paths.
- Apply CISA and vendor recommended ICS defense-in-depth practices while remediation is pending.
Evidence notes
This debrief is based on the CISA CSAF republishing of Siemens ProductCERT advisory SSA-032379, published 2026-05-12 and republished 2026-05-14. The advisory metadata names the product as Siemens SIMATIC CN 4100 and the vulnerability description as TCP SYN-driven resource exhaustion leading to denial of service. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The only documented remediation in the supplied corpus is to update to version 5.0 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-22925 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-22925
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-22925 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22925
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-032379.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.