CVE-2020-25241
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv440 Sr | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv440 Hr | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv440 Ur | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv420 Sr B | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv420 Sr P | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv420 Sr B Body | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.6 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Mv420 Sr P Body | All versions |
Related CWEs
CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.
CWE-129
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
References (2)
Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.