CVE-2025-40577: Medium severity siemens scalance lpe9403 firmware vulnerability
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40577?
CVE-2025-40577 is classified as a high severity vulnerability due to its potential to allow unauthenticated remote exploitation.
How do I fix CVE-2025-40577?
To mitigate the impact of CVE-2025-40577, it is recommended to apply the latest firmware updates from Siemens for the SCALANCE LPE9403 device.
What type of devices are affected by CVE-2025-40577?
CVE-2025-40577 affects all versions of the Siemens SCALANCE LPE9403 device.
What can an attacker do with CVE-2025-40577?
An attacker exploiting CVE-2025-40577 can send crafted Profinet packets, leading to a crash of the affected device.
Is authentication required to exploit CVE-2025-40577?
No, CVE-2025-40577 can be exploited by unauthenticated attackers, making it a significant security risk.