Siemens SIMATIC S7-1200 Improper Verification of Source of a Communication Channel (CVE-2025-40820)

high Tenable OT Security Plugin ID 505891

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Multiple Industrial products are affected by a vulnerability in the Interniche IP-Stack. The affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Siemens has released new versions for several affected products and recommends to update to the latest versions. For the SIMATIC S7-1200 CPU family (incl. SIPLUS variants), update to V4.4.0 or later version.

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security, and to follow the recommendations in the product manuals.

For more information see the associated Siemens security advisory SSA-915282 in HTML and CSAF.

See Also

https://cert-portal.siemens.com/productcert/html/ssa-915282.html

Plugin Details

Severity: High

ID: 505891

File Name: tenable_ot_siemens_CVE-2025-40820.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/30/2026

Updated: 7/30/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.36

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:siemens:simatic_s7-1200_cpu_firmware:4.4.0, cpe:/o:siemens:siplus_s7-1200_cpu_firmware:4.4.0

Required KB Items: Tenable.ot/Siemens

Patch Publication Date: 12/9/2025

Vulnerability Publication Date: 12/9/2025

Reference Information

CVE: CVE-2025-40820

CWE: 940