CVE Feed

    Dashboard / CVE / CVE-2025-40820

    CVE-2025-40820

    Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

    Published:Dec 9, 2025
    Last Modified:Apr 15, 2026
    EPS:Dec 9, 2025
    EPSS Score:0.00133
    CVSS Score:7.5

    Affected Products

    Vendor
    Siemens
    Product
    Sidoor Atd430w
    Vendor
    Siemens
    Product
    Sidoor Ate530s Coated
    Vendor
    Siemens
    Product
    Simatic
    Vendor
    Siemens
    Product
    Simatic Cfc
    Vendor
    Siemens
    Product
    Simatic Cfu Diq
    Vendor
    Siemens
    Product
    Simatic Cfu Pa
    Vendor
    Siemens
    Product
    Simatic Et200al Im 157-1 Pn
    Vendor
    Siemens
    Product
    Simatic Et200sp Im155-6 Mf Hf
    Vendor
    Siemens
    Product
    Simatic Et 200mp Im 155-5 Pn Hf
    Vendor
    Siemens
    Product
    Simatic Et 200s
    Vendor
    Siemens
    Product
    Simatic Pcs
    Vendor
    Siemens
    Product
    Simatic Pdm
    Vendor
    Siemens
    Product
    Simatic S7-1500 Cpu 1510sp-1 Pn
    Vendor
    Siemens
    Product
    Simatic S7-1500 Cpu 1510sp F-1 Pn
    Vendor
    Siemens
    Product
    Simatic S7-1500 Cpu 1512sp-1 Pn
    Vendor
    Siemens
    Product
    Simatic S7-1500 Cpu 1512sp F-1 Pn

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High