---
id: CVE-2025-40820
title: >-
  Affected products do not properly enforce TCP sequence number validation in
  specific scenarios but accept values within a broad range
summary: >-
  Affected products do not properly enforce TCP sequence number validation in
  specific scenarios but accept values within a broad range. This could allow an
  unauthenticated remote attacker e.g. to interfere with connection setup,
  potential…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-940
published: '2025-12-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40820'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-915282.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.0049
epssPercentile: 0.39804
ingestedAt: '2026-09-30T20:23:19.435Z'
---

## Overview

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
