CVE-2020-25241

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
siemenssimatic_mv440_sr_firmware
𝑥
< 7.0.6
siemenssimatic_mv440_hr_firmware
𝑥
< 7.0.6
siemenssimatic_mv440_ur_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-b_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-p_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-b_body_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-p_body_firmware
𝑥
< 7.0.6
𝑥
= Vulnerable software versions