Siemens Scalance Lpe9403 vulnerabilities

23 known vulnerabilities affecting siemens/scalance_lpe9403.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM10LOW4

Vulnerabilities

Page 2 of 2
CVE-2023-27408LOWCVSS 3.3vAll versions < V2.12023-05-09
CVE-2023-27408 [LOW] CWE-378 CVE-2023-27408: A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This could allow an authenticated attacker with access to the SSH interface on the affected device to interfere with the int
cvelistv5nvd
CVE-2023-27410LOWCVSS 2.7vAll versions < V2.12023-05-09
CVE-2023-27410 [LOW] CWE-122 CVE-2023-27410: A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer o A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an authenticated privileged attacker to cause a denial of service.
cvelistv5nvd
CVE-2023-27409LOWCVSS 3.3vAll versions < V2.12023-05-09
CVE-2023-27409 [LOW] CWE-22 CVE-2023-27409: A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vuln A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.
cvelistv5nvd