VYPR

Scalance Lpe9403 Firmware

by Siemens Foundation

CVEs (27)

  • CVE-2025-40575MedMay 13, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet,…

  • CVE-2025-27397LowMar 11, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit user controlled paths to which logs are written and from where they are read. This could allow an authenticated highly-privileged remote…

  • CVE-2021-4034HigKEVJan 28, 2022
    risk 0.23cvss 7.8epss 0.95

    A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the…

  • CVE-2023-27408LowMay 9, 2023
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This could allow an authenticated attacker with…

  • CVE-2025-27398LowMar 11, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly neutralize special characters when interpreting user controlled log paths. This could allow an authenticated highly-privileged remote attacker to…

  • CVE-2023-27410LowMay 9, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an…

  • CVE-2023-27409LowMay 9, 2023
    risk 0.16cvss 2.5epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read…

Page 2 of 2