IM
IronMonkey Threat Research

CVE-2025-40578 MEDIUM

Published: 2025-05-13 | Last Modified: 2025-06-04 | Status: Analyzed

Description

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which leads to a crash of the dcpd process.

Additional Descriptions (1)

Se ha identificado una vulnerabilidad en SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (todas las versiones). Los dispositivos afectados no gestionan correctamente múltiples paquetes Profinet entrantes recibidos en rápida sucesión. Un atacante remoto no autenticado puede explotar esta vulnerabilidad enviando múltiples paquetes en un periodo de tiempo muy corto, lo que provoca un bloqueo del proceso dcpd.

CVSS Metrics

Base Score: 4.3 (MEDIUM)

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactLOW

Source: [email protected]

Type: Secondary

Exploitability Score: 2.8

Impact Score: 1.4

Base Score: 5.3 (MEDIUM)

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorADJACENT
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredNONE
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityNONE
Vulnerability AvailabilityLOW
Subsequent ConfidentialityNONE
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-125

Affected Products

Vendor Product Version Update Type
siemens scalance_lpe9403_firmware - <built-in method update of dict object at 0x7d24246690c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_lpe9403_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:*
Notification
Message here