OTPulse

PwnKit Vulnerability in SCALANCE LPE9403 and SINUMERIK Edge Products (CVE-2021-4034)

Act Now7.8SSA-330556Jun 14, 2022
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

The products contain a local privilege escalation vulnerability (PwnKit / CVE-2021-4034) in the polkit pkexec utility that allows an unprivileged local user to gain administrative privileges on the affected device.

What this means
What could happen
An unprivileged user with local access to the device could gain administrative control, potentially allowing them to modify system configurations, disable safety features, or disrupt normal operations of the SCALANCE industrial switch or SINUMERIK Edge system.
Who's at risk
This vulnerability affects operators of Siemens SCALANCE LPE9403 industrial network switches and SINUMERIK Edge manufacturing control systems. Any facility using these products for energy or manufacturing automation should prioritize patching. The risk is highest in environments where staff or contractors have legitimate local access to these devices.
How it could be exploited
An attacker with local shell access (or who has obtained a standard user account on the device) can exploit a flaw in the pkexec utility to escalate their privileges to root without requiring valid administrative credentials. Once elevated, they can execute arbitrary commands with full system control.
Prerequisites
  • Local shell access to the affected device (SSH, console, or direct login)
  • Unprivileged user account on the system
actively exploited (KEV)high EPSS score (88.3%)low complexity exploitationlocal privilege escalation
Exploitability
Actively exploited — confirmed by CISA KEV
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
SCALANCE LPE9403< V2.02.0
SINUMERIK Edge< V3.3.03.3.0
Remediation & Mitigation
0/2
Do now
0/2
SCALANCE LPE9403
HOTFIXUpdate SCALANCE LPE9403 firmware to version 2.0 or later
SINUMERIK Edge
HOTFIXUpdate SINUMERIK Edge to version 3.3.0 or later
↑↓ Navigate · Esc Close
API: /api/v1/advisories/b2852b62-4455-46d8-9b61-27b4a1b093f8
PwnKit Vulnerability in SCALANCE LPE9403 and SINUMERIK Edge Products (CVE-2021-4034) | CVSS 7.8 - OTPulse