This could allow a privileged local attacker to restore backups that are outside the backup folder.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14673 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder. |
Tue, 08 Jul 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder. | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder. |
Fri, 30 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens scalance Lpe9403 Siemens scalance Lpe9403 Firmware |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:scalance_lpe9403_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens scalance Lpe9403 Siemens scalance Lpe9403 Firmware |
Tue, 13 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder. | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-07-08T10:34:37.967Z
Reserved: 2025-04-16T08:20:17.031Z
Link: CVE-2025-40573
Updated: 2025-05-13T18:43:28.177Z
Status : Modified
Published: 2025-05-13T10:15:26.773
Modified: 2025-07-08T11:15:27.797
Link: CVE-2025-40573
No data.
OpenCVE Enrichment
No data.
EUVD