This could allow a non-privileged local attacker to execute root commands on the device.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14664 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device. |
Fri, 30 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens scalance Lpe9403 Siemens scalance Lpe9403 Firmware |
|
| CPEs | cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:scalance_lpe9403_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens scalance Lpe9403 Siemens scalance Lpe9403 Firmware |
Tue, 13 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-05-13T13:12:51.317Z
Reserved: 2025-04-16T08:20:17.032Z
Link: CVE-2025-40582
Updated: 2025-05-13T13:12:35.997Z
Status : Analyzed
Published: 2025-05-13T10:15:28.537
Modified: 2025-05-30T17:07:00.713
Link: CVE-2025-40582
No data.
OpenCVE Enrichment
No data.
EUVD