IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403

HIGH
CVSS 7.8
Date 2026-09-08T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

// Vulnerabilities (12)

CVE ID CVSS Score Severity Description
CVE-2025-40575 4.3 medium
CVE-2025-40575. Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
CVE-2025-40576 4.3 medium
CVE-2025-40576. Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
CVE-2025-40580 6.7 medium
CVE-2025-40580. Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition.
CVE-2025-40582 7.8 high
CVE-2025-40582. Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device.
CVE-2025-40572 5.5 medium
CVE-2025-40572. Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local attacker to access sensitive information stored on the device.
CVE-2025-40583 4.4 medium
CVE-2025-40583. Affected devices do transmit sensitive information in cleartext. This could allow a privileged local attacker to retrieve this sensitive information.
CVE-2025-40574 7.8 high
CVE-2025-40574. Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local attacker to interact with the backupmanager service.
CVE-2025-40573 4.4 medium
CVE-2025-40573. Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder.
CVE-2025-40579 6.7 medium
CVE-2025-40579. Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition.
CVE-2025-40577 4.3 medium
CVE-2025-40577. Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
CVE-2025-40578 4.3 medium
CVE-2025-40578. Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which leads to a crash of the dcpd process.
CVE-2025-40581 7.1 high
CVE-2025-40581. Affected devices are vulnerable to an authentication bypass. This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
Siemens Unknown network_device -- --

// Remediations (5)

Mitigation: Restrict access to authorized and trusted personal only
Restrict access to authorized and trusted personal only
Patch: Update to V2.1 HF0 or later version Available on Industrial Edge Hub for ARM 64 and X86
Update to V2.1 HF0 or later version Available on Industrial Edge Hub for ARM 64 and X86
Mitigation: Restrict access to authorized and trusted personal only
Restrict access to authorized and trusted personal only
Patch: Update to V2.1 HF0 or later version Available on Industrial Edge Hub for ARM 64 and X86
Update to V2.1 HF0 or later version Available on Industrial Edge Hub for ARM 64 and X86
Mitigation: Restrict access to authorized and trusted personal only
Restrict access to authorized and trusted personal only

// References