Path Traversal Vulnerability in SCALANCE LPE9403 by Siemens
CVE-2023-27409
2.5LOW
What is CVE-2023-27409?
A security vulnerability has been discovered in SCALANCE LPE9403 devices where a path traversal issue exists within the deviceinfo
binary. By manipulating the mac
parameter, an authenticated attacker with SSH access could potentially read the contents of sensitive files, such as those named 'address'. This flaw highlights the importance of securing SSH interfaces to prevent unauthorized file access and protect sensitive configurations.
Affected Version(s)
SCALANCE LPE9403 All versions < V2.1