CVE-2020-25241

EUVD-2020-17931
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
siemenssimatic_mv440_sr_firmware
𝑥
< 7.0.6
siemenssimatic_mv440_hr_firmware
𝑥
< 7.0.6
siemenssimatic_mv440_ur_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-b_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-p_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-b_body_firmware
𝑥
< 7.0.6
siemenssimatic_mv420_sr-p_body_firmware
𝑥
< 7.0.6
𝑥
= Vulnerable software versions