CVE-2026-22924
9.1Siemens · SIMATIC CN 4100
A missing authentication vulnerability in Siemens SIMATIC CN 4100 allows unauthenticated attackers to trigger resource exhaustion and disrupt system operations.
Executive summary
A critical missing authentication vulnerability in Siemens SIMATIC CN 4100 permits unauthenticated attackers to cause resource exhaustion, resulting in potential service disruption.
Vulnerability
This vulnerability (CWE-306) stems from the application's failure to enforce authentication for critical communication functions. This allows an unauthenticated, remote attacker to interact with the device and consume system resources, leading to denial-of-service conditions.
Business impact
The ability for an unauthenticated attacker to disrupt industrial operations carries a significant risk to availability and system integrity. With a CVSS score of 9.1, this vulnerability represents a high risk to operational continuity, as the lack of authentication makes it easily exploitable from the network.
Remediation
Immediate Action: Update the Siemens SIMATIC CN 4100 to version V5.0 or later immediately to enforce necessary authentication controls.
Proactive Monitoring: Monitor network traffic for anomalous connection patterns or spikes in resource utilization that may indicate a denial-of-service attempt.
Compensating Controls: Deploy a firewall or industrial security appliance to restrict network access to the CN 4100, ensuring only authorized sources can communicate with the device.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for remote, unauthenticated exploitation, immediate patching is required. Organizations should isolate the affected hardware from untrusted networks until the firmware update can be successfully deployed.