CVE-2023-27409: Path Traversal
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the deviceinfo binary via the mac parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27409?
The severity of CVE-2023-27409 is low.
How does CVE-2023-27409 affect SCALANCE LPE9403?
CVE-2023-27409 affects SCALANCE LPE9403 (All versions < V2.1) through a path traversal vulnerability.
What is the impact of CVE-2023-27409?
CVE-2023-27409 allows an authenticated attacker with access to the SSH interface to read the contents of any file on the affected device.
How can I fix CVE-2023-27409?
To fix CVE-2023-27409, update SCALANCE LPE9403 firmware to version V2.1 or above.
Where can I find more information about CVE-2023-27409?
More information about CVE-2023-27409 can be found in the Siemens ProductCERT advisory: https://cert-portal.siemens.com/productcert/pdf/ssa-325383.pdf