Siemens SCALANCE LPE9403
cpe:2.3:h:siemens:scalance_lpe9403:*:*:*:*:*:*:*, +1 more
- < V4.0
A path traversal vulnerability has been identified in Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) all versions prior to 4.0. The vulnerability arises because affected devices do not properly restrict user-controlled paths for log file writing and reading. This flaw could enable an authenticated, highly privileged remote attacker to read and write arbitrary files in the filesystem, provided the malicious path ends with 'log'.
Exploitation of this vulnerability could lead to unauthorized reading and writing of files in the device's filesystem, potentially allowing for further exploitation or manipulation of the device.
Users are advised to update SCALANCE LPE9403 to version 4.0 or later. For more information, visit the Siemens Industry Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.