VDB
CVE-2023-27407
CVE-2023-27407
PUBLISHED
CVSS 8.600000381469727 HIGH
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user.
EPSS 1.30% · 68.8th percentile
Risk Scores
CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
1.30%
68.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SCALANCE LPE9403 | All versions < V2.1 |
| siemens | scalance_lpe9403_firmware | 0, 0 |
Timeline
- May 9, 2023 CVE Published
- May 10, 2023 EPSS Score
- Jun 16, 2023 EPSS Score
- Jul 23, 2023 EPSS Score
- Oct 5, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 18, 2023 EPSS Score
- Jan 24, 2024 EPSS Score
- Apr 8, 2024 EPSS Score
- May 15, 2024 EPSS Score
- Jun 21, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-789345.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-473245.html advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-325383.pdf advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-27407 advisory
- https://cert-portal.siemens.com/productcert/html/ssa-325383.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-932528.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-892048.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-555292.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-516174.html advisory