CVE-2026-22924
published 2026-05-12CVE-2026-22924: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections…
PriorityP358critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.30%
21.8th percentile
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions.
This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially impacting system availability and integrity.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_cn_4100 | < V5.0 | V5.0 |
| siemens | simatic_cn_4100_firmware | < 5.0 | 5.0 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9p8h-826j-wp3r: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5
ghsa_unreviewed·2026-05-12
CVE-2026-22924 [HIGH] CWE-306 GHSA-9p8h-826j-wp3r: A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions.
This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially impacting system availability and integrity.
CISA ICS
Siemens NX
cisa_ics·2026-02-12·CVSS 7.8
[HIGH] Siemens NX
ICS Advisory
##
Siemens NX
Release DateFebruary 12, 2026
Alert CodeICSA-26-043-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Siemens NX is affected by multiple file parsing vulnerabilities that could be triggered when the application reads files in CGM format. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for NX and recommends to update to the latest version.
The following versions of Siemens NX are affected:
- NX vers:intdot/<2512 (CVE-2026-22923, CVE-2026-22924, CVE-2026-22925)
CVSS
Vendor
Equipment
Vulnerabilities
| v3 7.8
| Siemens
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published