Skip to content
Nozomi Identifies 12 Vulnerabilities in Siemens SCALANCE LPE9403

Nozomi Identifies 12 Vulnerabilities in Siemens SCALANCE LPE9403

First seen 18 Sep 2026, 14:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 15:58 UTC
  • 12 vulnerabilities identified in Siemens SCALANCE LPE9403, affecting firmware below V4.0 HF0.
  • Exploitation could allow root access, impacting telemetry and operational data.
  • Siemens has issued patches; immediate updates and network segmentation are recommended.

Nozomi Networks Labs discovered 12 vulnerabilities in Siemens SCALANCE LPE9403 devices running firmware below V4.0 HF0, including privilege escalation and command injection flaws. These vulnerabilities, with CVSS scores from 5.3 to 8.5, can be exploited to gain root access and disrupt operational technology (OT) networks. Attackers could manipulate telemetry data, suppress alarms, or execute commands on connected systems. The vulnerabilities were responsibly reported to Siemens, which has since issued patches and advised users to apply updates immediately and implement network segmentation. The identified flaws include issues with the SINEMA Remote Connect Edge Client and DCP vulnerabilities, which can lead to significant impacts in industrial environments. Users are urged to monitor for vulnerable systems to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-05-13
CVE-2025-40575 to CVE-2025-40578 published
Four memory-corruption vulnerabilities in Siemens SCALANCE LPE9403 were disclosed, affecting firmware up to V4.0 HF0.
Industrialcyber.Co
2025-05-13
CVE-2025-40572 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-40582 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-40573 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-40581 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-40580 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-40574 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-40583 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
Nozomi identifies 12 vulnerabilities
Nozomi reported 12 vulnerabilities in Siemens SCALANCE LPE9403, enabling potential root access and OT network manipulation.
Industrialcyber.Co
2026-09-18
Siemens issues advisory and patches
Siemens published an advisory urging asset owners to review and apply updates immediately to mitigate risks from identified vulnerabilities.
Industrialcyber.Co

More articles in this cluster (3)

Following this threat?

Track Nozomi Networks Labs and CVE-2025-40572 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed