CVE-2025-40575: Medium severity siemens scalance lpe9403 firmware vulnerability
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40575?
CVE-2025-40575 has a high severity rating due to its potential to allow unauthenticated remote attacks.
How do I fix CVE-2025-40575?
To mitigate CVE-2025-40575, ensure that you apply the latest firmware updates provided by Siemens for the SCALANCE LPE9403.
What impacts can result from exploiting CVE-2025-40575?
Exploiting CVE-2025-40575 may lead to a crash of the SCALANCE LPE9403 device.
Who is affected by CVE-2025-40575?
CVE-2025-40575 affects all versions of the Siemens SCALANCE LPE9403 product.
What type of attack does CVE-2025-40575 involve?
CVE-2025-40575 involves an unauthenticated remote attack through specially crafted Profinet packets.