Permission Misconfiguration in SCALANCE LPE9403 by Siemens
CVE-2025-40574

8.5HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
13 May 2025

What is CVE-2025-40574?

A vulnerability has been identified in Siemens' SCALANCE LPE9403 device, where improper permission assignment may expose critical resources. This flaw enables a non-privileged local attacker to potentially exploit the backupmanager service, leading to unauthorized interactions with sensitive system components. Organizations using affected versions should review their security protocols to mitigate risks associated with this misconfiguration.

Affected Version(s)

SCALANCE LPE9403 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.