Heap-based Buffer Overflow Vulnerability in SCALANCE LPE9403 by Siemens
CVE-2023-27410

2.7LOW

Key Information:

Vendor
Siemens
Vendor
CVE Published:
9 May 2023

Summary

A heap-based buffer overflow vulnerability has been identified in the SCALANCE LPE9403 product from Siemens. This issue resides within the edgebox_web_app binary, which is susceptible to crashing when a backup password exceeding 255 characters is provided. An authenticated user with elevated privileges could exploit this vulnerability to induce a denial of service, making it crucial for users of SCALANCE LPE9403 to assess their systems and implement necessary security measures.

Affected Version(s)

SCALANCE LPE9403 All versions < V2.1

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.