IPv4 null pointer dereference causes denial of service on Siemens industrial devices

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-40833?

CVE-2025-40833 is a vulnerability classified as NULL Pointer Dereference, affecting IE/PB LINK HA (affected versions: < V4.1.2), IE/PB link PN IO (affected versions: 0), RUGGEDCOM RM1224 LTE(4G) EU (affected versions: < V8.3), and 143 more products. This vulnerability is rated High, with a CVSS score of 8.7. Current sources do not report this vulnerability as exploited.

Overview

Original source data

The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker to cause denial of service condition. A manual restart is required to recover the system.

Affected products and scope

The Siemens advisory identifies a broader affected scope than the initial normalized product list. Confirmed branches include:

• IE/PB LINK HA: all versions less than V4.1.2 are affected; Siemens specifies updating to V4.1.2 or a later version. • IE/PB link PN IO and the SIPLUS NET IE/PB link PN IO variant: all versions are affected; the advisory states that no fix is currently planned. • The SCALANCE M-800, SCALANCE MUM-800, SCALANCE S615, and RUGGEDCOM RM1224 families, including listed models such as M804PB, M812-1, M816-1, M826-2, M874-2, M874-3, M876-3, M876-4, MUB852-1, MUM853-1, and MUM856-1: all versions less than V8.3 are affected. • The advisory also lists additional SCALANCE W, SCALANCE SC, SCALANCE X, SCALANCE XR, SCALANCE XM, SIMATIC CFU, SIMATIC ET 200, SIMATIC S7 CPU, SIMIT, SINAMICS, SINUMERIK, and SITOP products. Examples with explicit fixed branches include listed SCALANCE WAM and WUM models below V3.2.0, listed SCALANCE W7xx models below V6.6.0, SIMATIC CFU below V2.0.0, SIMATIC ET 200SP HA below V1.3, SIMATIC S7-410 V8 below V8.3, and SIMATIC S7-410 V10 below V10.2. • Many other listed switches, controllers, drives, simulation products, and power products are affected in all versions, with no fix available or no fix planned at the advisory level. Status must be determined for the exact model and product number; unlisted branches should not be assumed unaffected.

Technical details

Siemens industrial devices contain a NULL pointer dereference flaw in the processing of specially crafted IPv4 requests. Attacker-controlled input can reach this network processing path and place the device into a denial of service condition. The supplied attack characteristics indicate network reachability, no authentication, no user interaction, and low attack complexity. The exact dereferenced pointer, packet structure, network service, and port are not disclosed. The affected scope includes industrial gateways, routers, switches, automation controllers, drives, I/O devices, and other industrial equipment listed by Siemens.

Exploitability

The flaw can be reached remotely over IPv4 networking. The supplied attack characteristics indicate that an attacker does not need an account, special privileges, or user interaction, and no complex condition is identified. The normalized record marks a public exploit as false; returned NVD change data also includes CISA SSVC information recording exploitation as none at its recorded timestamp. This is time-bounded information and does not prove that exploitation has never occurred in every environment. No exploit code, campaign, victim, or specific compromise indicator is identified in the available evidence.

Technical impact

The flaw can make a device unavailable after it receives a specially crafted IPv4 request, producing a denial of service for the functions the device provides. Recovery requires a manual restart, so the interruption may last longer than a normal transient network failure. Because the attack path is network reachable and does not require authentication, devices exposed to untrusted or unnecessary IPv4 sources present greater operational risk. For equipment involved in industrial control or communications, the outage could affect dependent systems, although the extent depends on network design and redundancy. The available record does not establish data access, data modification, privilege escalation, or code execution.

Business impact

• An affected device may stop providing network or communications services until it is manually restarted. • For routers, switches, gateways, controllers, or industrial I/O interfaces, an outage could interrupt communications between PLCs, HMIs, field devices, and control systems, depending on the redundancy architecture. • Manual recovery can require on-site intervention and create operational downtime. • The record describes an availability impact; it does not establish direct data disclosure or data modification. • The practical consequence depends on the device role, IPv4 reachability from external or less-trusted networks, and the availability of failover or redundant equipment.

Remediation

  1. For branches with confirmed fixes, upgrade each model to the exact Siemens release specified for that branch: V4.1.2 for IE/PB LINK HA; V8.3 for the SCALANCE M-800, SCALANCE MUM-800, SCALANCE S615, and RUGGEDCOM RM1224 branches; V3.2.0 for listed SCALANCE WAM or WUM models; V6.6.0 for listed SCALANCE W7xx models; V2.0.0 for listed SIMATIC CFU models; V1.3 for SIMATIC ET 200SP HA; V8.3 for SIMATIC S7-410 V8; and V10.2 for SIMATIC S7-410 V10.
  2. Do not apply a fix from one product branch to a parallel branch unless the advisory confirms it. Products marked as affected in all versions but lacking a fix still require model-specific handling.
  3. For products without an available or planned fix, restrict access to affected systems to trusted IP addresses and place the devices in a protected network segment.
  4. For the SIMATIC S7-400 CPU families specifically identified by Siemens, disable the CPU Ethernet ports and use a communications module, such as a CP module, for communications. Siemens also documents this measure for SIMATIC S7-410 families where mitigation is needed.
  5. Plan manual restart capability during a maintenance window for devices that become unavailable. A restart is recovery after an outage, not a substitute for firmware remediation or network mitigation.

Detection

  1. Inventory Siemens devices from the IE/PB LINK, SCALANCE, RUGGEDCOM, SIMATIC, SINAMICS, SINUMERIK, SITOP, and related product families, recording the exact model, product number, and running firmware.
  2. Compare each model and firmware level with the affected branches in the Siemens advisory. Do not assume that a parallel product branch is safe because another branch has a fix.
  3. Identify devices whose IPv4 interfaces are reachable from untrusted or unnecessary network zones, then review access control lists and source restrictions.
  4. Review availability events, communication interruptions, and manual restart requirements that follow unusual IPv4 traffic. This is precautionary monitoring, not a Siemens-confirmed indicator of exploitation.
  5. After upgrading or applying mitigation, verify the firmware level, management status, and device communications. No specific log signature or packet-level indicator has been published for confirming exploitation.
Sources (17)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan