← All Advisories

Siemens SCALANCE LPE9403's Authentication Bypass Allows Non-Privileged Local Attackers to Bypass Authentication Controls on Affected Versions

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2025-40581

Key Details

CVECVE-2025-40581
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsSiemens SCALANCE LPE9403 Firmware
Classified asCWE-288 (Authentication Bypass Using an Alternate Path or Channel)
Exploitation prediction (EPSS)0.15% probability of exploitation in the next 30 days (4% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSCALANCE LPE9403 Firmware
SubsystemsOEM Remote Access Gateways, SCADA/HMI Platform
SectorsCritical Manufacturing, Energy

What to Know

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.

This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.

What to Do

Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigation: Restrict access to authorized and trusted personal only.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-40581
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-40581
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-327438.html