First published: Wed Mar 10 2021(Updated: )
In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constant increments. An attacker could predict and hijack TCP sessions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic Mv420 Firmware | <7.0.6 | |
Siemens Simatic Mv420 | ||
Siemens Simatic Mv440 Firmware | <7.0.6 | |
Siemens Simatic Mv440 | ||
Multiple Nut/Net, Version 5.1 and prior | ||
Multiple CycloneTCP, Version 1.9.6 and prior | ||
Multiple NDKTCPIP, Version 2.25 and prior | ||
Multiple FNET, Version 4.6.3 | ||
Multiple uIP-Contiki-OS (end-of-life [EOL]), Version 3.0 and prior | ||
Multiple uC/TCP-IP (EOL), Version 3.6.0 and prior | ||
Multiple uIP-Contiki-NG, Version 4.5 and prior | ||
Multiple uIP (EOL), Version 1.0 and prior | ||
Multiple picoTCP-NG, Version 1.7.0 and prior | ||
Multiple picoTCP (EOL), Version 1.7.0 and prior | ||
Multiple MPLAB Net, Version 3.6.1 and prior | ||
Multiple Nucleus NET, All versions prior to Version 5.2 | ||
Multiple Nucleus ReadyStart for ARM, MIPS, and PPC, All versions prior to Version 2012.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27632 is a vulnerability in SIMATIC MV400 family versions prior to v7.0.6 where the ISN generator is initialized with a constant value and has constant increments, allowing an attacker to predict and hijack TCP sessions.
SIMATIC MV400 family versions prior to v7.0.6 are affected by CVE-2020-27632.
CVE-2020-27632 has a severity rating of 7.5 (high).
To fix CVE-2020-27632, it is recommended to update the affected SIMATIC MV400 family device to version v7.0.6 or later.
You can find more information about CVE-2020-27632 at the following references: [Siemens CERT Portal](https://cert-portal.siemens.com/productcert/pdf/ssa-599268.pdf), [CISA ICS Advisories](https://www.cisa.gov/news-events/ics-advisories/icsa-21-042-01), [Forescout - Numberjack Weak ISN Generation in Embedded TCP/IP Stacks](https://www.forescout.com/resources/numberjack-weak-isn-generation-in-embedded-tcpip-stacks/).