Status: UPDATED | Advisory ID: CVE-2025-40581
| CVE | CVE-2025-40581 |
| CVSS | CVSS 7.1 (High): attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) |
| Affected products | Siemens SCALANCE LPE9403 Firmware |
| Classified as | CWE-288 (Authentication Bypass Using an Alternate Path or Channel) |
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.
This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.
Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigation: Restrict access to authorized and trusted personal only.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2025-40581 |
| Vendor advisory | https://cert-portal.siemens.com/productcert/html/ssa-327438.html |