Impact
A vulnerability in the SIMATIC CN 4100 allows an attacker to trigger resource exhaustion by sending a high volume of TCP SYN packets. This leads to denial of service, effectively rendering the system unavailable. The weakness is a classic instance of resource exhaustion, cataloged as CWE-770.
Affected Systems
Siemens SIMATIC CN 4100 (all versions prior to V5.0) are affected by this issue. No specific patch version is provided in the advisory; a firmware upgrade to V5.0 or later would remove the vulnerability.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no currently known active exploitation. The attack vector is likely network-based: an adversary could launch a TCP SYN flood from outside the local network to overwhelm the controller's resources. Given the lack of an official workaround, administrators should treat this as a priority threat if the device is exposed to external networks.
OpenCVE Enrichment