Vulnerabilities > CVE-2020-27632 - Unspecified vulnerability in Siemens Simatic Mv420 Firmware and Simatic Mv440 Firmware

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
siemens

Summary

In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constant increments. An attacker could predict and hijack TCP sessions.

Vulnerable Configurations

Part Description Count
OS
Siemens
2
Hardware
Siemens
2