CVE-2025-40578: Medium severity siemens scalance lpe9403 firmware vulnerability
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which leads to a crash of the dcpd process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40578?
CVE-2025-40578 has been classified as a critical vulnerability due to its potential to allow unauthenticated remote code execution.
What are the effects of CVE-2025-40578?
Exploitation of CVE-2025-40578 can lead to denial of service and possible control over affected devices.
How do I fix CVE-2025-40578?
To mitigate CVE-2025-40578, it is recommended to apply the latest security patches provided by Siemens for SCALANCE LPE9403.
Who is affected by CVE-2025-40578?
All versions of Siemens SCALANCE LPE9403 devices are vulnerable to CVE-2025-40578.
Is there a workaround for CVE-2025-40578?
Currently, no official workaround is available for CVE-2025-40578 other than applying the recommended updates.