Siemens Industrial Devices Null Pointer Dereference Vulnerability Leading to Denial-of-Service

Vulnerability

A null pointer dereference vulnerability has been identified in multiple Siemens industrial devices. This vulnerability arises when the devices process specially crafted IPv4 requests, potentially allowing an attacker to cause a denial-of-service condition. The issue requires a manual restart to recover the system.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the affected system to become unresponsive and requiring a manual restart to restore normal operation.

Remediation

Siemens has released patches for some affected products. For products where no fix is available, it is recommended to restrict access to the affected systems to trusted IP addresses only. Specific update instructions can be found on the Siemens Industry Support website.

Added: May 12, 2026, 11:03 AM
Updated: May 12, 2026, 11:03 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
7.0
remediation
7.9
relevance
8.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.