
12 vulnerabilities in Siemens SCALANCE LPE9403 enable chained root access, telemetry manipulation, and lateral movement across OT networks. Patch to firmware V4.0 HF0 or above immediately. - CVE-2025-40572, CVE-2025-40573, and CVE-2025-40574 chain to escalate a read-only local account to root on the LPE9403 (CVSS up to 8.5). From there, an attacker controls telemetry before it reaches SCADA, falsifying sensor values and suppressing alarms while the physical process runs in an unsafe state. - If SINEMA Remote Connect Edge Client V2.1 or below is installed, CVE-2025-40582 (command injection) lets a compromised SINEMA server push root commands to every connected LPE device. One rogue server becomes multi-site OT compromise. CVE-2025-40581 adds authentication bypass; CVE-2025-40583 exposes credentials in cleartext. - The second attack path requires only SSH access plus the SINEMA auth bypass to redirect the client to an attacker-controlled server, triggering the command injection and achieving root without touching the SINEMA infrastructure at all. - Impact at root: credential and config exfiltration, network mapping of OT assets, service disruption, and persistent footholds that bridge separate OT segments for lateral movement. Update SCALANCE LPE9403 firmware to V4.0 HF0, segment the device from untrusted networks, and audit SINEMA Remote Connect server trust relationships. #DFIR_Radar
