CVE-2025-27393: OS Command Injection
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new users. This could allow an authenticated highly-privileged remote attacker to execute arbitrary code on the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SCALANCE LPE9403 (6GK5998-3GS00-2AC2)to a version that resolves this vulnerability.Fixed in V4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27393?
CVE-2025-27393 is considered a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-27393?
To fix CVE-2025-27393, you should upgrade to version 4.0 or later of the Siemens SCALANCE LPE9403.
What devices are affected by CVE-2025-27393?
CVE-2025-27393 affects all versions of the Siemens SCALANCE LPE9403 prior to version 4.0.
Who can exploit CVE-2025-27393?
An authenticated, highly-privileged remote attacker can exploit CVE-2025-27393 due to improper input sanitization.
What are the consequences of CVE-2025-27393?
The consequences of CVE-2025-27393 include the potential for an attacker to execute arbitrary code on the vulnerable device.