PT-2021-2229 · Siemens · Simatic Mv400

Published

2021-03-05

·

Updated

2023-10-10

·

CVE-2020-27632

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC MV400 family versions prior to v7.0.6
Description The issue is related to the implementation of the ISN generator in the TI-NDKTCPIP protocol stack, which uses insufficiently random values. This could allow a remote attacker to predict and hijack TCP sessions, potentially gaining unauthorized access to protected information.
Recommendations For SIMATIC MV400 family versions prior to v7.0.6, update to version v7.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected system to minimize the risk of exploitation.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

BDU:2021-01174
CVE-2020-27632

Affected Products

Simatic Mv400