CVE-2020-25241
—CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
Description
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.
- Vendors
- siemens
- Products
- simatic mv440 sr firmware, simatic mv440 hr firmware, simatic mv440 ur firmware, simatic mv420 sr-b firmware, simatic mv420 sr-p firmware, simatic mv420 sr-b body firmware, simatic mv420 sr-p body firmware
- Weakness
- CWE-1285, CWE-129
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.