CVE-2025-40574: High severity siemens scalance lpe9403 firmware vulnerability
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local attacker to interact with the backupmanager service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40574?
The severity of CVE-2025-40574 is classified as medium due to the impact on critical resource permissions.
How do I fix CVE-2025-40574?
To fix CVE-2025-40574, update the SCALANCE LPE9403 firmware to the latest recommended version.
Who is affected by CVE-2025-40574?
All versions of the SCALANCE LPE9403 (6GK5998-3GS00-2AC2) are affected by CVE-2025-40574.
What is the nature of the vulnerability in CVE-2025-40574?
CVE-2025-40574 involves improper assignment of permissions to critical resources that can be exploited by local attackers.
What is the potential impact of CVE-2025-40574?
The potential impact of CVE-2025-40574 includes unauthorized interactions with the backupmanager service by non-privileged users.