Siemens has updates available to handle predictable exact value from previous values vulnerability in its APOGEE PXC/TALON TC, according to a report with CISA.
Successful exploitation of this remotely exploitable vulnerability, which Siemens self-reported, could allow an attacker to hijack existing sessions or spoof future sessions.
The following products suffer from the issue:
- APOGEE PXC Series (BACnet): All versions prior to 3.5.5
- APOGEE PXC Series (P2 Ethernet): All versions prior to 2.8.20
- TALON TC Series (BACnet): All versions prior to 3.5.5
In the vulnerability, initial sequence numbers (ISNs) for TCP connections are derived from an insufficiently random source; the ISN of current and future TCP connections could be predictable. An attacker could hijack existing sessions or spoof future sessions.
CVE-2020-28388 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.5.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
- Siemens has identified the following workarounds and mitigations users can apply to reduce risk:
- APOGEE PXC Series (P2 Ethernet): Update to V2.8.20 or later versionsÂ
- APOGEE PXC Series (BACnet): Update to V3.5.5 or later versionsÂ
- TALON TC Series (BACnet): Update to V3.5.5 or later versionsÂ
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and to follow the recommendations in the product manuals.
For more information, click on Siemens security advisory SSA-408105.
No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.

