cbcvebase.
CVE-2023-27407
published 2023-05-09

CVE-2023-27407: A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user…

PriorityP267critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
1.30%
67.0th percentile
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemensscalance_lpe9403
siemensscalance_lpe9403_firmware< 2.12.1

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-27407 is a command injection vulnerability in the web-based management interface of SCALANCE LPE9403; monitor for authenticated remote HTTP requests containing shell metacharacters or command separators in user-input fields of the web management interface.
  • Exploitation results in OS-level root access; alert on unexpected root-level process spawning from the web application process (e.g., edgebox_web_app) on SCALANCE LPE9403 devices.
  • The companion heap-based buffer overflow (CVE-2023-27410) in the 'edgebox_web_app' binary is triggered by a backup password longer than 255 characters; monitor for abnormally long password fields in backup-related web requests to the device.
  • The companion path traversal (CVE-2023-27409) targets the 'deviceinfo' binary via the 'mac' parameter over SSH; monitor for SSH sessions invoking 'deviceinfo' with path traversal sequences (e.g., '../') in the mac parameter.
  • The companion insecure mutex vulnerability (CVE-2023-27408) involves the i2c mutex file created with world-writable permissions (-rw-rw-rw-); monitor for unexpected writes to the i2c mutex file from non-privileged processes on the device.
  • ·All versions of SCALANCE LPE9403 (6GK5998-3GS00-2AC2) prior to V2.1 are affected; exploitation requires only low-privilege authenticated access (PR:L) with no user interaction and has a Changed scope, yielding a CVSS v3 score of 9.9.
  • ·No known public exploits specifically target these vulnerabilities at time of advisory publication, but the low attack complexity and network-accessible attack vector make it high priority to patch or isolate.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.