Core issue
This can be normal traffic, but the embryonic limit is not high enough. The PIX can also experience a TCP syn flood attack.
Resolution
Check the source addresses that are reported and if they are valid addresses that should have access, then the embryonic limit should be increased. Refer to the nat command for more information.
If the traffic appears to be unwanted connection attempts, then the traffic can be blocked on the PIX with an access list or on a router or other device outside the PIX. The ISP can also be able to block the source.