CVE-2020-25241

HIGH

SIMATIC MV400 Family < 7.0.6 - TCP Session Termination via Invalid RST Sequence Number

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0103
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1285 CWE-129
Status published
Products (7)
siemens/simatic_mv420_sr-b_body_firmware < 7.0.6
siemens/simatic_mv420_sr-b_firmware < 7.0.6
siemens/simatic_mv420_sr-p_body_firmware < 7.0.6
siemens/simatic_mv420_sr-p_firmware < 7.0.6
siemens/simatic_mv440_hr_firmware < 7.0.6
siemens/simatic_mv440_sr_firmware < 7.0.6
siemens/simatic_mv440_ur_firmware < 7.0.6
Published Mar 15, 2021
Tracked Since Feb 18, 2026