PatchSiren cyber security CVE debrief
CVE-2025-40580 Siemens CVE debrief
CVE-2025-40580 affects Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2) and was published on 2025-05-13. The advisory says a stack-based buffer overflow could allow a non-privileged local attacker to execute arbitrary code on the device or trigger a denial-of-service condition. Siemens/CISA list no fix available at publication time and recommend restricting access to authorized and trusted personnel only.
- Vendor
- Siemens
- Product
- SCALANCE LPE9403 (6GK5998-3GS00-2AC2)
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-13
- Original CVE updated
- 2025-05-13
- Advisory published
- 2025-05-13
- Advisory updated
- 2025-05-13
Who should care
Industrial control system operators, plant engineers, network administrators, and security teams responsible for Siemens SCALANCE LPE9403 devices in operational environments.
Technical summary
The CSAF advisory for CVE-2025-40580 identifies a stack-based buffer overflow in the Siemens SCALANCE LPE9403 product family. The stated impact is local attack execution by a non-privileged attacker, with possible arbitrary code execution or denial of service. The supplied CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H, which aligns with a medium severity assessment. The source advisory also records that no fix is currently available.
Defensive priority
Medium. The issue is serious because it may permit code execution or device outage, but the attack requires local access and other conditions reflected in the CVSS vector. Prioritize if the device is reachable by untrusted users or shared in a plant network.
Recommended defensive actions
- Restrict device access to authorized and trusted personnel only, as recommended in the advisory.
- Limit local access paths, shared accounts, and maintenance interfaces that could expose the device to non-privileged users.
- Review network and physical access controls around SCALANCE LPE9403 deployments.
- Monitor Siemens and CISA advisory pages for a vendor fix or updated mitigation guidance.
- Apply general ICS defense-in-depth practices from CISA resources while no patch is available.
Evidence notes
All material facts in this debrief come from the supplied CISA CSAF advisory and its referenced Siemens/CISA links. The advisory states the affected product, vulnerability type, impact, no-fix status, and mitigation. The publication date used here is the CVE/advisory publication date of 2025-05-13, not any later processing date.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40580 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40580
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40580 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40580
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-135-18.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-327438.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-327438.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-18
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.