{"id":"CVE-2025-40820","title":"Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range","summary":"Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potential…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-940"],"published":"2025-12-09","updated":"2026-09-30","sourceUpdated":"2026-09-30T20:10:00.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40820","references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-915282.html","label":"productcert@siemens.com"}],"tags":["nvd"],"epss":0.0049,"epssPercentile":0.39804,"ingestedAt":"2026-09-30T20:23:19.435Z","slug":"CVE-2025-40820","body":"## Overview\n\nAffected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}