#VU51379 Input validation error in SIMATIC MV400 - CVE-2020-25241
Published: March 10, 2021
SIMATIC MV400
Siemens
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.