Path Traversal Vulnerability in SCALANCE LPE9403 by Siemens
CVE-2025-40573

6.7MEDIUM

Key Information:

Vendor

Siemens

Vendor
CVE Published:
13 May 2025

What is CVE-2025-40573?

A path traversal vulnerability has been discovered in SCALANCE LPE9403 devices, which could enable a privileged local attacker to manipulate backup files. This exploit allows attackers to retrieve backups stored outside the designated backup directory, potentially leading to unauthorized access to sensitive information. It is crucial for enterprises utilizing affected devices to implement security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

SCALANCE LPE9403 0

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.