Lucene search

K
cveSiemensCVE-2023-27407
HistoryMay 09, 2023 - 1:15 p.m.

CVE-2023-27407

2023-05-0913:15:16
CWE-78
CWE-77
siemens
web.nvd.nist.gov
18
vulnerability
scalance lpe9403
authenticated remote attacker
root access
cve-2023-27407
command injection
nvd

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

49.7%

A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.

Affected configurations

Nvd
Node
siemensscalance_lpe9403_firmwareRange<2.1
AND
siemensscalance_lpe9403Match-
VendorProductVersionCPE
siemensscalance_lpe9403_firmware*cpe:2.3:o:siemens:scalance_lpe9403_firmware:*:*:*:*:*:*:*:*
siemensscalance_lpe9403-cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SCALANCE LPE9403",
    "versions": [
      {
        "version": "All versions < V2.1",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

49.7%

Related for CVE-2023-27407