CVE-2020-27632: Siemens SIMATIC MV420 Firmware

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constant increments. An attacker could predict and hijack TCP sessions.

Affected products

  • Siemens SIMATIC MV420 Firmware: before 7.0.6 (fixed in 7.0.6)
  • Siemens SIMATIC MV440 Firmware: before 7.0.6 (fixed in 7.0.6)

Published 2021-03-10. Last modified 2026-06-17.