CVE Database
/

CVE-2025-40820

Back to search

CVE-2025-40820

Published: Dec 9, 2025

Modified: Dec 9, 2025

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

VendorProductVersions

Siemens

SIDOOR ATD430W

affected
0 - < *

Siemens

SIDOOR ATE530G COATED

affected
0 - < *

Siemens

SIDOOR ATE530S COATED

affected
0 - < *

Siemens

SIMATIC CFU DIQ

affected
0 - < V2.0.0

Siemens

SIMATIC CFU PA

affected
0 - < V2.0.0

Siemens

SIMATIC CFU PA

affected
0 - < V2.0.0

Siemens

SIMATIC ET 200AL IM 157-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200clean, CM 8x IO-Link

affected
0 - < *

Siemens

SIMATIC ET 200clean, DI 16x24VDC

affected
0 - < *

Siemens

SIMATIC ET 200clean, DIQ 16x24VDC/0,5A

affected
0 - < *

Siemens

SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, CM 4x IO-Link, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, DI 16x24VDC, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, DI 8x24VDC, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, DIQ 16x24VDC/2A, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, DQ 8x24VDC/0,5A, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200eco PN, DQ 8x24VDC/2A, M12-L

affected
V5.1.1 - < *

Siemens

SIMATIC ET 200MP IM 155-5 PN HF

affected
V4.2.0 - < *

Siemens

SIMATIC ET 200pro IM 154-8 PN/DP CPU

affected
0 - < *

Siemens

SIMATIC ET 200pro IM 154-8F PN/DP CPU

affected
0 - < *

Siemens

SIMATIC ET 200pro IM 154-8FX PN/DP CPU

affected
0 - < *

Siemens

SIMATIC ET 200S IM 151-8 PN/DP CPU

affected
0 - < *

Siemens

SIMATIC ET 200S IM 151-8F PN/DP CPU

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1510SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP CPU 1512SP-1 PN

affected
0 - < *

Siemens

SIMATIC ET 200SP IM 155-6 MF HF

affected
0 - < *

Siemens

SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants)

affected
0 - < V1.3

Siemens

SIMATIC ET 200SP IM 155-6 PN HF

affected
V4.2.0 - < *

Siemens

SIMATIC ET 200SP IM 155-6 PN/2 HF

affected
V4.2.0 - < *

Siemens

SIMATIC ET 200SP IM 155-6 PN/3 HF

affected
V4.2.0 - < *

Siemens

SIMATIC PN/MF Coupler

affected
0 - < *

Siemens

SIMATIC PN/PN Coupler

affected
0 - < V6.0.0

Siemens

SIMATIC Power Line Booster PLB, Base Module

affected
0 - < *

Siemens

SIMATIC Power Line Booster PLB, Modem Module ST

affected
0 - < *

Siemens

SIMATIC S7-1200 CPU 1211C AC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1211C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1211C DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1212C AC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1212C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1212C DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1212FC DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1212FC DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1214C AC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1214C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1214C DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1214FC DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1214FC DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1215C AC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1215C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1215C DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1215FC DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1215FC DC/DC/Rly

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1200 CPU 1217C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIMATIC S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1515F-2 PN

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU CR40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU CR60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST60

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 314C-2 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 315-2 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 315F-2 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 315T-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 317-2 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 317F-2 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 317T-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 317TF-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 319-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-300 CPU 319F-3 PN/DP

affected
0 - < *

Siemens

SIMATIC S7-400 CPU 412-2 PN V7

affected
0 - < *

Siemens

SIMATIC S7-400 CPU 414-3 PN/DP V7

affected
0 - < *

Siemens

SIMATIC S7-400 CPU 414F-3 PN/DP V7

affected
0 - < *

Siemens

SIMATIC S7-400 CPU 416-3 PN/DP V7

affected
0 - < *

Siemens

SIMATIC S7-400 CPU 416F-3 PN/DP V7

affected
0 - < *

Siemens

SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants)

affected
0 - < *

Siemens

SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants)

affected
0 - < V10.2

Siemens

SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants)

affected
0 - < V8.3

Siemens

SIMATIC TDC CP51M1

affected
0 - < *

Siemens

SIMATIC TDC CPU555

affected
0 - < *

Siemens

SIMOCODE pro V Ethernet/IP (incl. SIPLUS variants)

affected
0 - < *

Siemens

SIMOCODE pro V PROFINET

affected
0 - < *

Siemens

SINUMERIK 840D sl

affected
0 - < *

Siemens

SIPLUS ET 200MP IM 155-5 PN HF

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200MP IM 155-5 PN HF

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200S IM 151-8 PN/DP CPU

affected
0 - < *

Siemens

SIPLUS ET 200S IM 151-8F PN/DP CPU

affected
0 - < *

Siemens

SIPLUS ET 200SP CPU 1512SP F-1 PN

affected
0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL

affected
V4.2.0 - < *

Siemens

SIPLUS ET 200SP IM 155-6 PN HF TX RAIL

affected
V4.2.0 - < *

Siemens

SIPLUS HCS4200 CIM4210

affected
0 - < *

Siemens

SIPLUS HCS4200 CIM4210C

affected
0 - < *

Siemens

SIPLUS HCS4300 CIM4310

affected
0 - < *

Siemens

SIPLUS NET PN/PN Coupler

affected
0 - < V6.0.0

Siemens

SIPLUS S7-1200 CPU 1212 AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1212 DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1212 DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1212C AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1212C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1212C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214 AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214 DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214C DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214FC DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1214FC DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215 DC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215C AC/DC/RLY

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215C DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1200 CPU 1215FC DC/DC/DC

affected
0 - < V4.4.0

Siemens

SIPLUS S7-1500 CPU 1511-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1511F-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1513-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1513F-1 PN

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-1500 CPU 1516F-3 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-300 CPU 314C-2 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-300 CPU 315-2 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-300 CPU 315F-2 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-300 CPU 317-2 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-300 CPU 317F-2 PN/DP

affected
0 - < *

Siemens

SIPLUS S7-400 CPU 414-3 PN/DP V7

affected
0 - < *

Siemens

SIPLUS S7-400 CPU 416-3 PN/DP V7

affected
0 - < *

Siemens

SIWAREX WP231

affected
0 - < *

Siemens

SIWAREX WP241

affected
0 - < *

Siemens

SIWAREX WP251

affected
0 - < *

Siemens

SIWAREX WP521 ST

affected
0 - < *

Siemens

SIWAREX WP522 ST

affected
0 - < *

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now