Siemens
Siemens Scalance Lpe9403 Firmware: vulnerabilidades y CVE
Siemens Scalance Lpe9403 Firmware tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses0
Críticas1
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2022-0847 | Alta (7.8) | 93% | ⚠ Explotación activa | 10 mar 2022 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-40583 | Media (6.7) | 0.11% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext.… |
| CVE-2025-40582 | Alta (8.5) | 0.18% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration… |
| CVE-2025-40581 | Alta (8.4) | 0.15% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This… |
| CVE-2025-40580 | Media (5.4) | 0.16% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker… |
| CVE-2025-40579 | Media (5.4) | 0.16% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker… |
| CVE-2025-40578 | Media (5.3) | 0.27% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated… |
| CVE-2025-40577 | Media (5.3) | 0.27% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit… |
| CVE-2025-40576 | Media (5.3) | 0.27% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit… |
| CVE-2025-40575 | Media (5.3) | 0.46% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit… |
| CVE-2025-40574 | Alta (8.5) | 0.14% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local… |
| CVE-2025-40573 | Media (6.7) | 0.17% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore… |
| CVE-2025-40572 | Media (6.8) | 0.14% | — | 13 may 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local… |
| CVE-2025-27398 | Baja (2.1) | 0.33% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly neutralize special characters when interpreting user controlled log paths. This could… |
| CVE-2025-27397 | Media (5.1) | 0.40% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit user controlled paths to which logs are written and from where they are read.… |
| CVE-2025-27396 | Alta (8.7) | 0.43% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the elevation of privileges required to perform certain valid functionality.… |
| CVE-2025-27395 | Alta (8.6) | 0.65% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the scope of files accessible through and the privileges of the SFTP… |
| CVE-2025-27394 | Alta (8.6) | 0.73% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new SNMP users. This could allow an authenticated… |
| CVE-2025-27393 | Alta (8.6) | 0.73% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new users. This could allow an authenticated… |
| CVE-2025-27392 | Alta (8.6) | 0.73% | — | 11 mar 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new VXLAN configurations. This could allow an… |
| CVE-2023-27410 | Baja (2.7) | 0.56% | — | 9 may 2023 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup… |
| CVE-2023-27409 | Baja (3.3) | 0.17% | — | 9 may 2023 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with… |
| CVE-2023-27408 | Baja (3.3) | 0.17% | — | 9 may 2023 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications… |
| CVE-2023-27407 | Crítica (9.9) | 1.3% | — | 9 may 2023 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could… |
| CVE-2022-0847 | Alta (7.8) | 93% | ⚠ Explotación activa | 10 mar 2022 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale… |
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2021-36221 | Media (5.9) | 3.1% | — | 8 ago 2021 | Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort. |
| CVE-2021-3449 | Media (5.9) | 64% | — | 25 mar 2021 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the… |