{"document":{"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Disclosure is not limited. (TLPv2: TLP:CLEAR)","tlp":{"label":"WHITE"}},"lang":"en","notes":[{"category":"summary","text":"SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality.\n\nSiemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.","title":"Summary"},{"category":"general","text":"As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity","title":"General Recommendations"},{"category":"general","text":"For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories","title":"Additional Resources"},{"category":"legal_disclaimer","text":"The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"productcert@siemens.com","name":"Siemens ProductCERT","namespace":"https://www.siemens.com"},"references":[{"category":"self","summary":"SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403 - HTML Version","url":"https://cert-portal.siemens.com/productcert/html/ssa-327438.html"},{"category":"self","summary":"SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403 - CSAF Version","url":"https://cert-portal.siemens.com/productcert/csaf/ssa-327438.json"}],"title":"SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403","tracking":{"current_release_date":"2026-09-08T00:00:00.000Z","generator":{"engine":{"name":"Siemens ProductCERT CSAF Generator","version":"1"}},"id":"SSA-327438","initial_release_date":"2025-05-13T00:00:00.000Z","revision_history":[{"date":"2025-05-13T00:00:00.000Z","legacy_version":"1.0","number":"1","summary":"Publication Date"},{"date":"2025-07-08T00:00:00.000Z","legacy_version":"1.1","number":"2","summary":"Added fix for CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40579, CVE-2025-40580"},{"date":"2026-09-08T00:00:00.000Z","legacy_version":"1.2","number":"3","summary":"Added fix for devices with SINEMA Remote Connect Edge Client installed"}],"status":"interim","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"vers:intdot/<4.0.0","product":{"name":"SCALANCE LPE9403 (6GK5998-3GS00-2AC2) < V4.0.0","product_id":"1","product_identification_helper":{"model_numbers":["6GK5998-3GS00-2AC2"]}}},{"category":"product_version_range","name":"vers:all/*","product":{"name":"SCALANCE LPE9403 (6GK5998-3GS00-2AC2)","product_id":"2","product_identification_helper":{"model_numbers":["6GK5998-3GS00-2AC2"]}}},{"category":"product_version_range","name":"vers:intdot/<2.1.0","product":{"name":"SCALANCE LPE9403 (6GK5998-3GS00-2AC2) < V2.1.0 with SINEMA Remote Connect Edge Client installed","product_id":"3","product_identification_helper":{"model_numbers":["6GK5998-3GS00-2AC2"]}}}],"category":"product_name","name":"SCALANCE LPE9403 (6GK5998-3GS00-2AC2)"}],"category":"vendor","name":"Siemens"}]},"vulnerabilities":[{"cve":"CVE-2025-40572","cwe":{"id":"CWE-732","name":"Incorrect Permission Assignment for Critical Resource"},"notes":[{"category":"description","text":"Affected devices do not properly assign permissions to critical ressources.\r\nThis could allow a non-privileged local attacker to access sensitive information stored on the device.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40572"},{"cve":"CVE-2025-40573","cwe":{"id":"CWE-35","name":"Path Traversal: '.../...//'"},"notes":[{"category":"description","text":"Affected devices are vulnerable to path traversal attacks.\r\nThis could allow a privileged local attacker to restore backups that are outside the backup folder.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40573"},{"cve":"CVE-2025-40574","cwe":{"id":"CWE-732","name":"Incorrect Permission Assignment for Critical Resource"},"notes":[{"category":"description","text":"Affected devices do not properly assign permissions to critical ressources.\r\nThis could allow a non-privileged local attacker to interact with the backupmanager service.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40574"},{"cve":"CVE-2025-40575","cwe":{"id":"CWE-457","name":"Use of Uninitialized Variable"},"notes":[{"category":"description","text":"Affected devices do not properly validate incoming Profinet packets.\r\nAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd\r\nprocess.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Disable the Profinet Discovery and Configuration Protocol (DCP) service","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40575"},{"cve":"CVE-2025-40576","cwe":{"id":"CWE-476","name":"NULL Pointer Dereference"},"notes":[{"category":"description","text":"Affected devices do not properly validate incoming Profinet packets.\r\nAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Disable the Profinet Discovery and Configuration Protocol (DCP) service","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40576"},{"cve":"CVE-2025-40577","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"Affected devices do not properly validate incoming Profinet packets.\r\nAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Disable the Profinet Discovery and Configuration Protocol (DCP) service","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40577"},{"cve":"CVE-2025-40578","cwe":{"id":"CWE-125","name":"Out-of-bounds Read"},"notes":[{"category":"description","text":"Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession.\r\nAn unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which leads to a crash of the dcpd process.","title":"CVE Description"}],"product_status":{"known_affected":["2"]},"remediations":[{"category":"mitigation","details":"Disable the Profinet Discovery and Configuration Protocol (DCP) service","product_ids":["2"]},{"category":"no_fix_planned","details":"Currently no fix is planned","product_ids":["2"]}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["2"]}],"title":"CVE-2025-40578"},{"cve":"CVE-2025-40579","cwe":{"id":"CWE-121","name":"Stack-based Buffer Overflow"},"notes":[{"category":"description","text":"Affected devices are vulnerable to a stack-based buffer overflow.\r\nThis could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":6.7,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40579"},{"cve":"CVE-2025-40580","cwe":{"id":"CWE-121","name":"Stack-based Buffer Overflow"},"notes":[{"category":"description","text":"Affected devices are vulnerable to a stack-based buffer overflow.\r\nThis could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition.","title":"CVE Description"}],"product_status":{"known_affected":["1"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["1"]},{"category":"vendor_fix","details":"Update to V4.0 HF0 or later version","product_ids":["1"],"url":"https://support.industry.siemens.com/cs/ww/en/view/109989944/"}],"scores":[{"cvss_v3":{"baseScore":6.7,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["1"]}],"title":"CVE-2025-40580"},{"cve":"CVE-2025-40581","cwe":{"id":"CWE-288","name":"Authentication Bypass Using an Alternate Path or Channel"},"notes":[{"category":"description","text":"Affected devices are vulnerable to an authentication bypass.\r\nThis could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.","title":"CVE Description"}],"product_status":{"known_affected":["3"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["3"]},{"category":"vendor_fix","details":"Update to V2.1 HF0 or later version\nAvailable on Industrial Edge Hub for ARM 64 and X86","product_ids":["3"]}],"scores":[{"cvss_v3":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["3"]}],"title":"CVE-2025-40581"},{"cve":"CVE-2025-40582","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"Affected devices do not properly sanitize configuration parameters.\r\nThis could allow a non-privileged local attacker to execute root commands on the device.","title":"CVE Description"}],"product_status":{"known_affected":["3"]},"remediations":[{"category":"mitigation","details":"Only use trusted SINEMA Remote Connect Servers","product_ids":["3"]},{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["3"]},{"category":"vendor_fix","details":"Update to V2.1 HF0 or later version\nAvailable on Industrial Edge Hub for ARM 64 and X86","product_ids":["3"]}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["3"]}],"title":"CVE-2025-40582"},{"cve":"CVE-2025-40583","cwe":{"id":"CWE-319","name":"Cleartext Transmission of Sensitive Information"},"notes":[{"category":"description","text":"Affected devices do transmit sensitive information in cleartext.\r\nThis could allow a privileged local attacker to retrieve this sensitive information.","title":"CVE Description"}],"product_status":{"known_affected":["3"]},"remediations":[{"category":"mitigation","details":"Restrict access to authorized and trusted personal only","product_ids":["3"]},{"category":"vendor_fix","details":"Update to V2.1 HF0 or later version\nAvailable on Industrial Edge Hub for ARM 64 and X86","product_ids":["3"]}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["3"]}],"title":"CVE-2025-40583"}]}