CVE-2020-28388: Siemens Capital Vstar
Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus ReadyStart V3 (All versions < V2012.12), Nucleus Source Code (All versions), PLUSCONTROL 1st Gen (All versions), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). Initial Sequence Numbers (ISNs) for TCP connections are derived from an insufficiently random source. As a result, the ISN of current and future TCP connections could be predictable. An attacker could hijack existing sessions or spoof future ones.
Affected products
- Siemens Capital Vstar: any version
- Siemens Nucleus Net: before 5.2 (fixed in 5.2)
- Siemens Nucleus Readystart: before 2012.12 (fixed in 2012.12)
- Siemens Nucleus Source Code: any version
- Siemens Pluscontrol 1st Gen: any version
Published 2021-02-09. Last modified 2026-06-17.