CVE-2025-40583

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a privileged local attacker to retrieve this sensitive information.
References
Link Resource
https://cert-portal.siemens.com/productcert/html/ssa-327438.html Vendor Advisory Mitigation
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:scalance_lpe9403_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:*

History

30 May 2025, 17:06

Type Values Removed Values Added
First Time Siemens scalance Lpe9403
Siemens
Siemens scalance Lpe9403 Firmware
CPE cpe:2.3:o:siemens:scalance_lpe9403_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-327438.html - () https://cert-portal.siemens.com/productcert/html/ssa-327438.html - Vendor Advisory, Mitigation
Summary
  • (es) Se ha identificado una vulnerabilidad en SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (todas las versiones con SINEMA Remote Connect Edge Client instalado). Los dispositivos afectados transmiten información confidencial en texto plano. Esto podría permitir que un atacante local con privilegios obtenga esta información confidencial.

13 May 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 10:15

Updated : 2025-05-30 17:06


NVD link : CVE-2025-40583

Mitre link : CVE-2025-40583

CVE.ORG link : CVE-2025-40583


JSON object : View

Products Affected

siemens

  • scalance_lpe9403
  • scalance_lpe9403_firmware
CWE
CWE-319

Cleartext Transmission of Sensitive Information