CVE-2020-25241: Siemens SIMATIC MV420 Sr-B Body Firmware
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP sessions.
Affected products
- Siemens SIMATIC MV420 Sr-B Body Firmware: before 7.0.6 (fixed in 7.0.6)
- Siemens SIMATIC MV420 Sr-B Firmware: before 7.0.6 (fixed in 7.0.6)
- Siemens SIMATIC MV420 Sr-P Body Firmware: before 7.0.6 (fixed in 7.0.6)
- Siemens SIMATIC MV420 Sr-P Firmware: before 7.0.6 (fixed in 7.0.6)
- Siemens SIMATIC MV440 Hr Firmware: before 7.0.6 (fixed in 7.0.6)
- Siemens SIMATIC MV440 Sr Firmware: before 7.0.6 (fixed in 7.0.6)
- Siemens SIMATIC MV440 Ur Firmware: before 7.0.6 (fixed in 7.0.6)
Published 2021-03-15. Last modified 2026-06-17.