← All Advisories

CVE-2025-40582

Status: UPDATED  |  Advisory ID: CVE-2025-40582

Key Details

CVECVE-2025-40582
CVSSCVSS 7.8 (High): attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected productsSiemens SCALANCE LPE9403 Firmware
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters.

This could allow a non-privileged local attacker to execute root commands on the device.

What to Do

Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigations: Only use trusted SINEMA Remote Connect Servers; Restrict access to authorized and trusted personal only.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-40582
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-327438.html