← Vulnerability feed

Vulnerability record · CVE-2022-25622 · published 12 April 2022

CVE-2022-25622: Siemens simatic cfu diq firmware uncontrolled resource consumption vulnerability

Siemens · Simatic Cfu Diq Firmware

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

7.5 CVSS 3.1 High EPSS 0.88% · top 42.4% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score, v2 5.0
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25622 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2020-28400Siemens dk standard ethernet controller evaluation kit firmware allocation without limits vulnerabilityAffected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be t…EPSS 1.9%8.3CVE-2014-2251Siemens simatic s7-1500 cpu firmware vulnerabilityThe random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it ea…EPSS 2.7%8.2CVE-2018-16557Siemens simatic s7-400 firmware improper verification of cryptographic signature vulnerabilityA vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 C…EPSS 0.82%7.8CVE-2014-2255Siemens simatic s7-1500 cpu firmware vulnerabilitySiemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…EPSS 4.5%7.8CVE-2014-2257Siemens simatic s7-1500 cpu firmware vulnerabilitySiemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…EPSS 3.5%7.8CVE-2014-2259Siemens simatic s7-1500 cpu firmware vulnerabilitySiemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…EPSS 4.5%7.5CVE-2021-40368Siemens simatic s7-400h v6 firmware memory buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 C…EPSS 1.0%7.5CVE-2019-19300Siemens ktk ate530s firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERT…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2022-25622), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.