← All Advisories

Siemens SCALANCE LPE9403's Configuration Parameter Handling Flaw Lets Non-Privileged Local Attackers Execute Commands as Root When SINEMA Remote Connect Edge Client Is Installed

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2025-40582

Key Details

CVECVE-2025-40582
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens SCALANCE LPE9403 Firmware
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Exploitation prediction (EPSS)0.18% probability of exploitation in the next 30 days (7% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSCALANCE LPE9403 Firmware
SubsystemsOEM Remote Access Gateways, SCADA/HMI Platform
SectorsCritical Manufacturing, Energy

What to Know

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters.

This could allow a non-privileged local attacker to execute root commands on the device.

What to Do

Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigations: Only use trusted SINEMA Remote Connect Servers; Restrict access to authorized and trusted personal only.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-40582
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-40582
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-327438.html