CVE-2019-10926: Siemens SIMATIC MV420 Firmware

Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.

Affected products

  • Siemens SIMATIC MV420 Firmware: any version
  • Siemens SIMATIC MV440 Firmware: any version

Published 2019-06-12. Last modified 2026-06-17.