


Perceptive Security
SOC/SIEM Consultancy

Siemens Interniche IP-Stack
Published:
18 December 2025 at 12:00:00
Alert date:
18 December 2025 at 18:04:12
Source:
cisa.gov
Multiple Siemens industrial products are affected by CVE-2025-40820, a vulnerability in the InterNiche IP-Stack that allows unauthenticated remote attackers to interfere with TCP connection setup, potentially causing denial of service. The vulnerability affects TCP sequence number validation and impacts over 140 different Siemens products including SIMATIC S7 series, ET 200 series, and other industrial automation systems. Attacks require precise timing and spoofed IP packets. Siemens has released fixes for some products and recommends specific countermeasures for others.
Technical details
Mitigation steps:
Affected products:
Siemens InterNiche IP-Stack
SIMATIC S7-1200
SIMATIC S7-1500
SIMATIC S7-300
SIMATIC S7-400
SIMATIC ET 200
SIDOOR
SINUMERIK
SIWAREX
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-05
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-05.json
https://nvd.nist.gov/vuln/detail/CVE-2025-40820
https://cwe.mitre.org/data/definitions/940.html
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
https://www.siemens.com/cert/operational-guidelines-industrial-security
https://www.siemens.com/industrialsecurity
https://www.siemens.com/cert/advisories
https://www.siemens.com/productcert/terms-of-use
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
