← Back

CVE-2020-25241

nvd nist
Published: Mar 15, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.

Affected (7)

7 products
Simatic Mv440 Sr Firmware
Simatic Mv440 Hr Firmware
Simatic Mv440 Ur Firmware
Simatic Mv420 Sr B Firmware
Simatic Mv420 Sr P Firmware
Simatic Mv420 Sr B Body Firmware
Simatic Mv420 Sr P Body Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv440 Sr
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv440 Hr
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv440 Ur
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv420 Sr B
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv420 Sr P
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv420 Sr B Body
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.0.6
Running on/withPlatform Versions
Siemens
Simatic Mv420 Sr P Body
All versions

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.