Industrialcyber.Co Nozomi Identifies 12 Vulnerabilities in Siemens SCALANCE LPE9403
Article Content
- •12 vulnerabilities identified in Siemens SCALANCE LPE9403, affecting firmware below V4.0 HF0.
- •Exploitation could allow root access, impacting telemetry and operational data.
- •Siemens has issued patches; immediate updates and network segmentation are recommended.
Nozomi Networks Labs discovered 12 vulnerabilities in Siemens SCALANCE LPE9403 devices running firmware below V4.0 HF0, including privilege escalation and command injection flaws. These vulnerabilities, with CVSS scores from 5.3 to 8.5, can be exploited to gain root access and disrupt operational technology (OT) networks. Attackers could manipulate telemetry data, suppress alarms, or execute commands on connected systems. The vulnerabilities were responsibly reported to Siemens, which has since issued patches and advised users to apply updates immediately and implement network segmentation. The identified flaws include issues with the SINEMA Remote Connect Edge Client and DCP vulnerabilities, which can lead to significant impacts in industrial environments. Users are urged to monitor for vulnerable systems to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Nozomi Networks Labs and CVE-2025-40572 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…