CVE-2025-40577 Details
Description
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
A denial-of-service vulnerability has been identified in Siemens SCALANCE LPE9403 devices (6GK5998-3GS00-2AC2, all versions). The issue arises because affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted malicious packet, causing the dcpd process to crash.
Siemens recommends disabling the Profinet Discovery and Configuration Protocol (DCP) service on affected devices. For general security, it is advised to protect network access to devices with appropriate measures and to follow Siemens' operational guidelines for Industrial Security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-327438.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens scalance lpe9403 firmware | All versions |
CPE
Remediation
| |
| siemens scalance lpe9403 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2025 | CVE Modified | [email protected] |
| Jun 4, 2025 | Initial Analysis | [email protected] |
| May 13, 2025 | New CVE Received | [email protected] |