CVE-2023-27407

CRITICAL

SCALANCE LPE9403 < 2.1 - Authenticated OS Command Injection via Web Management Interface

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.

References (1)

Core 1

Scores

CVSS v3 9.9
EPSS 0.0118
EPSS Percentile 79.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-77
Status published
Products (1)
siemens/scalance_lpe9403_firmware < 2.1
Published May 09, 2023
Tracked Since Feb 18, 2026