Vulnerabilities > CVE-2025-40575 - Use of Uninitialized Variable vulnerability in Siemens Scalance Lpe9403 Firmware

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
network
low complexity
siemens
CWE-457

Summary

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.

Vulnerable Configurations

Part Description Count
OS
Siemens
1
Hardware
Siemens
1

Common Weakness Enumeration (CWE)