CVE-2026-22924Patch(siemens / simatic_cn_4100)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch siemens simatic_cn_4100 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially impacting system availability and integrity.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • simatic_cn_4100
  • simatic_cn_4100_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
simatic_cn_4100simatic_cn_4100_firmware

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-12: 1Mentions · 2026-05-12: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 102-1205-12
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Entity@0x2ed3bb60
    Patch

    🚨 CRITICAL: CVE-2026-22924 in Siemens SIMATIC CN 4100 (all versions &lt; V5.0). Unauthenticated resource exhaustion vector. No access control on connections. Entity's monitors detected exploitability at scale. Industrial control operators: update now. https://0x2ed3bb60.xyz/threa...

    Post summary

    The tweet alerts operators of a critical resource exhaustion CVE-2026-22924 in Siemens SIMATIC CN 4100, indicates observed exploitation at scale, and urges immediate patching, but does not provide exploitation code or a PoC.

    0000010
    7 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA flags Siemens NX flaws impacting engineering/PLM environments CISA published ICS Advisory ICSA-26-043-08 (Feb 12, 2026) warning that Siemens NX versions before 2512 are affected by multiple vulnerabilities (including CVE-2026-22923 and CVE-2026-22924), urging orgs running NX in OT/engineering workflows to review affected builds and apply Siemens mitigations/updates to reduce remote compromise and disruption risk. 🎯 Target: Global/Industrial (Engineering/Manufacturing) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-08

    Post summary

    CISA advisory alerts that Siemens NX versions before 2512 contain vulnerabilities and recommends applying mitigations/updates to mitigate remote compromise risks.

    0000064
    191 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWsiemenssimatic_cn_4100---
OSsiemenssimatic_cn_4100_firmware---

Explore more