Description
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.
Published: 2023-05-09
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-31185 A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.
History

Tue, 28 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Siemens Scalance Lpe9403 Scalance Lpe9403 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-01-28T16:47:12.923Z

Reserved: 2023-03-01T13:17:28.869Z

Link: CVE-2023-27409

cve-icon Vulnrichment

Updated: 2024-08-02T12:09:43.343Z

cve-icon NVD

Status : Modified

Published: 2023-05-09T13:15:16.800

Modified: 2024-11-21T07:52:51.343

Link: CVE-2023-27409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses