CVE-2023-27410: Buffer Overflow
Published May 9, 2023
·Updated
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the edgeboxwebapp binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an authenticated privileged attacker to cause a denial of service.
Affected Software
2 affected components
Siemens Scalance Lpe9403 Firmware<2.1
Siemens SCALANCE LPE9403
Event History
May 9, 2023
CVE Published
via MITRE·11:51 AM
Data Sourced
via MITRE·11:51 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-27410.
2
What is the affected software?
The affected software is SCALANCE LPE9403 (All versions < V2.1).
3
What is the severity of CVE-2023-27410?
The severity of CVE-2023-27410 is low.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-119 and CWE-122.
5
How can I fix the vulnerability?
To fix the vulnerability, update SCALANCE LPE9403 firmware to version 2.1 or higher.