Siemens SCALANCE LPE9403
SCALANCE LPE9403 industrial network switch (firmware versions prior to V2.1) is affected by multiple vulnerabilities including command injection (CWE-77), improper resource validation (CWE-378), path traversal (CWE-22), and buffer overflow (CWE-122). These flaws allow an authenticated attacker to compromise the confidentiality, integrity, and availability of the device. The switch is a critical component in industrial networks; compromise could disrupt communication between PLCs, RTUs, and other control devices.
- Network access to the SCALANCE LPE9403 management interface (typically port 80/443 or console)
- Valid login credentials for the device (user account)
- Device must be running firmware version prior to V2.1
Patching may require device reboot — plan for process interruption
/api/v1/advisories/d9638cd7-7434-480d-9a61-d9060b66d691Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.