First published: Tue May 13 2025(Updated: )
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Scalance LPE9403 Firmware | <= |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-40576 is categorized as a critical vulnerability due to its potential for unauthorized remote exploitation.
To mitigate CVE-2025-40576, ensure that you update your SCALANCE LPE9403 firmware to the latest version available from Siemens.
CVE-2025-40576 allows an unauthenticated attacker to send malicious Profinet packets, which can lead to a device crash.
CVE-2025-40576 affects all versions of the Siemens SCALANCE LPE9403 model.
No, CVE-2025-40576 can be exploited by unauthenticated attackers.