First published: Tue May 13 2025(Updated: )
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Scalance LPE9403 Firmware | <=Infinity |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-40573 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2025-40573, ensure that your SCALANCE LPE9403 firmware is updated to the latest version provided by Siemens.
CVE-2025-40573 involves a path traversal attack that can allow an attacker to access backups outside of the designated backup folder.
Any user operating the SCALANCE LPE9403 device is affected by CVE-2025-40573 regardless of the firmware version currently in use.
No, CVE-2025-40573 requires local access to the device for exploitation.