← All Advisories

CVE-2026-22924

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-22924

Key Details

CVECVE-2026-22924
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-06-29
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsSiemens SIMATIC CN 4100 and Siemens simatic_cn_4100_firmware
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMATIC CN 4100
Siemenssimatic_cn_4100_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions.

This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially impacting system availability and integrity. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-22924
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-22924
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-032379.html