CVE-2025-40581: High severity Siemens SCALANCE LPE9403 vulnerability
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SCALANCE LPE9403 (6GK5998-3GS00-2AC2)to a version that resolves this vulnerability.Fixed in V2.1 HF0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40581?
CVE-2025-40581 has been rated as a high-severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2025-40581?
To address CVE-2025-40581, it is recommended to update the SCALANCE LPE9403 firmware to the latest version provided by Siemens.
Who is affected by CVE-2025-40581?
CVE-2025-40581 impacts all versions of the SCALANCE LPE9403 with the SINEMA Remote Connect Edge Client installed.
What type of attack is possible with CVE-2025-40581?
CVE-2025-40581 allows a non-privileged local attacker to bypass authentication mechanisms.
What product is involved in CVE-2025-40581?
The product involved in CVE-2025-40581 is the Siemens SCALANCE LPE9403.