CVE-2025-40820
7.5Siemens · SIDOOR and SIMATIC CFU
Siemens industrial products fail to properly validate TCP sequence numbers, allowing unauthenticated remote attackers to interfere with connection setup and cause a denial of service.
Executive summary
A critical vulnerability in various Siemens industrial controllers allows unauthenticated remote attackers to disrupt network communications via TCP sequence number manipulation.
Vulnerability
This vulnerability involves improper verification of source communication channels, specifically failing to enforce TCP sequence number validation. An unauthenticated remote attacker can exploit this by injecting spoofed IP packets to interrupt or prevent legitimate TCP connections, resulting in a denial of service.
Business impact
The inability to maintain stable TCP connections on critical industrial hardware can lead to significant operational disruption and loss of process availability. Because the attack vector is remote and requires no authentication, the potential for unauthorized interference with production environments is high. The CVSS score of 7.5 reflects the high impact on service availability despite the technical difficulty of precise packet timing.
Remediation
Immediate Action: Consult the official Siemens security advisory (SSA-915282) to identify specific firmware updates or configuration changes required for your hardware revision.
Proactive Monitoring: Monitor network traffic for anomalous TCP traffic patterns, specifically focusing on out-of-sequence packets or unexpected connection resets targeting your Siemens industrial controllers.
Compensating Controls: Implement network segmentation and strictly control access to industrial control networks, ensuring that devices are not exposed directly to the public internet or untrusted segments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the exposure of industrial control systems, it is vital to prioritize the assessment of your Siemens hardware inventory against these affected versions. Administrators should apply vendor-provided patches as soon as they become available to eliminate the risk of remote denial-of-service attacks against critical infrastructure.