PatchSiren cyber security CVE debrief
CVE-2025-40572 Siemens CVE debrief
CVE-2025-40572 affects Siemens SCALANCE LPE9403 and was published on 2025-05-13. The issue is an improper permissions problem on critical resources that could let a non-privileged local attacker access sensitive information stored on the device. The advisory classifies the issue as medium severity and notes that no fix was available at publication, with mitigation focused on restricting access to authorized and trusted personnel.
- Vendor
- Siemens
- Product
- SCALANCE LPE9403 (6GK5998-3GS00-2AC2)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-13
- Original CVE updated
- 2025-05-13
- Advisory published
- 2025-05-13
- Advisory updated
- 2025-05-13
Who should care
OT/ICS operators, Siemens SCALANCE LPE9403 administrators, site reliability teams managing industrial network equipment, and defenders responsible for local access control on affected devices.
Technical summary
According to the CISA CSAF advisory and Siemens references, affected SCALANCE LPE9403 devices do not properly assign permissions to critical resources. The resulting exposure is local and requires a non-privileged attacker with local access. The stated impact is confidentiality-only: sensitive information stored on the device may be accessed, while integrity and availability impacts are not described in the source. The provided CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, which aligns with a local, low-privilege disclosure issue.
Defensive priority
Medium. The CVSS score is 5.5, but the lack of an available fix at publication and the potential exposure of sensitive device data make this worth prompt operational attention in environments where local access cannot be tightly controlled.
Recommended defensive actions
- Restrict physical and local access to authorized and trusted personnel only, as stated in the advisory.
- Review who can log in to or otherwise interact locally with the affected SCALANCE LPE9403 devices.
- Apply Siemens and CISA advisory guidance as it becomes available, since the source states no fix was available at publication.
- Treat device-local credential, configuration, and other sensitive data on affected units as potentially exposed if unauthorized local access is possible.
- Follow CISA ICS recommended practices and defense-in-depth guidance for access control and segmentation.
Evidence notes
The source corpus consistently identifies Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) as the affected product. The advisory description states that permissions to critical resources are not properly assigned and that a non-privileged local attacker could access sensitive information stored on the device. The remediation section says to restrict access to authorized and trusted personnel and also states that no fix is currently available. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, published and modified on 2025-05-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40572 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40572
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40572 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40572
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-135-18.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-327438.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-327438.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-18
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.