CVE-2025-40576: Null Pointer Dereference
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40576?
CVE-2025-40576 is categorized as a critical vulnerability due to its potential for unauthorized remote exploitation.
How do I fix CVE-2025-40576?
To mitigate CVE-2025-40576, ensure that you update your SCALANCE LPE9403 firmware to the latest version available from Siemens.
What impact does CVE-2025-40576 have on my device?
CVE-2025-40576 allows an unauthenticated attacker to send malicious Profinet packets, which can lead to a device crash.
Which devices are affected by CVE-2025-40576?
CVE-2025-40576 affects all versions of the Siemens SCALANCE LPE9403 model.
Is authentication required to exploit CVE-2025-40576?
No, CVE-2025-40576 can be exploited by unauthenticated attackers.