CVE-2025-40582(siemens / scalance_lpe9403)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • scalance_lpe9403
  • scalance_lpe9403_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
scalance_lpe9403scalance_lpe9403_firmware

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-18: 109-18
Full discourse1 post
  • DFIR Radar@DFIR_Radar

    12 vulnerabilities in Siemens SCALANCE LPE9403 enable chained root access, telemetry manipulation, and lateral movement across OT networks. Patch to firmware V4.0 HF0 or above immediately. - CVE-2025-40572, CVE-2025-40573, and CVE-2025-40574 chain to escalate a read-only local account to root on the LPE9403 (CVSS up to 8.5). From there, an attacker controls telemetry before it reaches SCADA, falsifying sensor values and suppressing alarms while the physical process runs in an unsafe state. - If SINEMA Remote Connect Edge Client V2.1 or below is installed, CVE-2025-40582 (command injection) lets a compromised SINEMA server push root commands to every connected LPE device. One rogue server becomes multi-site OT compromise. CVE-2025-40581 adds authentication bypass; CVE-2025-40583 exposes credentials in cleartext. - The second attack path requires only SSH access plus the SINEMA auth bypass to redirect the client to an attacker-controlled server, triggering the command injection and achieving root without touching the SINEMA infrastructure at all. - Impact at root: credential and config exfiltration, network mapping of OT assets, service disruption, and persistent footholds that bridge separate OT segments for lateral movement. Update SCALANCE LPE9403 firmware to V4.0 HF0, segment the device from untrusted networks, and audit SINEMA Remote Connect server trust relationships. #DFIR_Radar

    30010180
    1.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWsiemensscalance_lpe9403---
OSsiemensscalance_lpe9403_firmware---

Explore more