CVE-2025-40573: Path Traversal
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40573?
CVE-2025-40573 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2025-40573?
To fix CVE-2025-40573, ensure that your SCALANCE LPE9403 firmware is updated to the latest version provided by Siemens.
What type of attack does CVE-2025-40573 involve?
CVE-2025-40573 involves a path traversal attack that can allow an attacker to access backups outside of the designated backup folder.
Who is affected by CVE-2025-40573?
Any user operating the SCALANCE LPE9403 device is affected by CVE-2025-40573 regardless of the firmware version currently in use.
Can CVE-2025-40573 be exploited remotely?
No, CVE-2025-40573 requires local access to the device for exploitation.