PT-2025-10741 · Siemens · Scalance Lpe9403

Published

2025-03-11

·

Updated

2025-03-11

·

CVE-2025-27396

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCALANCE LPE9403 versions prior to V4.0
Description A issue has been identified where affected devices do not properly limit the elevation of privileges required to perform certain valid functionality. This could allow an authenticated remote attacker with low privileges to escalate their privileges.
Recommendations For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to functions that require privilege elevation until a patch is available.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03171
CVE-2025-27396

Affected Products

Scalance Lpe9403