7.5
CVE-2020-25241
- EPSS 0.39%
- Published 15.03.2021 17:15:20
- Last modified 21.11.2024 05:17:44
- Source productcert@siemens.com
- Teams watchlist Login
- Open Login
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.
Data is provided by the National Vulnerability Database (NVD)
Siemens ≫ Simatic Mv440 Sr Firmware Version < 7.0.6
Siemens ≫ Simatic Mv440 Hr Firmware Version < 7.0.6
Siemens ≫ Simatic Mv440 Ur Firmware Version < 7.0.6
Siemens ≫ Simatic Mv420 Sr-b Firmware Version < 7.0.6
Siemens ≫ Simatic Mv420 Sr-p Firmware Version < 7.0.6
Siemens ≫ Simatic Mv420 Sr-b Body Firmware Version < 7.0.6
Siemens ≫ Simatic Mv420 Sr-p Body Firmware Version < 7.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.39% | 0.57 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input
The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.