CVE-2023-27409: Siemens Scalance LPE9403 Firmware

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.

Affected products

  • Siemens Scalance LPE9403 Firmware: before 2.1 (fixed in 2.1)

Published 2023-05-09. Last modified 2026-06-17.