Description
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.
Published: 2023-05-09
Score: 9.9 Critical
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-31183 A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.
History

Tue, 28 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Siemens Scalance Lpe9403 Scalance Lpe9403 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-01-28T18:51:06.264Z

Reserved: 2023-03-01T13:17:28.868Z

Link: CVE-2023-27407

cve-icon Vulnrichment

Updated: 2024-08-02T12:09:43.369Z

cve-icon NVD

Status : Modified

Published: 2023-05-09T13:15:16.640

Modified: 2024-11-21T07:52:51.077

Link: CVE-2023-27407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses