← All Advisories

CVE-2025-40581

Status: UPDATED  |  Advisory ID: CVE-2025-40581

Key Details

CVECVE-2025-40581
CVSSCVSS 7.1 (High): attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Affected productsSiemens SCALANCE LPE9403 Firmware
Classified asCWE-288 (Authentication Bypass Using an Alternate Path or Channel)

What to Know

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.

This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.

What to Do

Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigation: Restrict access to authorized and trusted personal only.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-40581
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-327438.html