Vulnerabilities · 4h ago

Nozomi Found Four Flaws in Siemens OT Gateway

Nozomi Networks Labs found four memory-corruption bugs in Siemens SCALANCE LPE9403 firmware up to V4.0 HF0, tracked as CVE-2025-40575 through CVE-2025-40578. The affected component is the PROFINET Discovery and basic Configuration Protocol (DCP) daemon on the industrial PC, which runs as root and listens without authentication.

That matters because DCP works at Layer 2 for discovery and basic network setup. A machine on the same local segment can send crafted Ethernet packets to crash the daemon, which can make devices look unreachable to SCADA systems or stop a new device from getting an IP address during deployment.

The exposure sits in the gateway layer that sits between PLCs and higher-level control systems, so the blast radius is visibility and provisioning at the network edge, not just one host. Siemens has fixed the flaws in the latest firmware; for plants that use the LPE9403 as a preprocessing or gateway node, the remaining question is how much trust they place in its reachability path.

CVE-2025-40575

NVD KEV

CVSS 4.3 MEDIUM: a vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). EPSS 0.5% (39th percentile).

CVE-2025-40576

NVD KEV

CVSS 4.3 MEDIUM: a vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). EPSS 0.3% (18th percentile).

CVE-2025-40577

NVD KEV

CVSS 4.3 MEDIUM: a vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). EPSS 0.3% (18th percentile).

CVE-2025-40578

NVD KEV

CVSS 4.3 MEDIUM: a vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). EPSS 0.3% (18th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-15

Editions

Related stories