Vulnerabilities · 3 days ago

Siemens SCALANCE Flaws Can Cascade to OT Root Access

Nozomi Networks Labs disclosed 12 vulnerabilities in Siemens SCALANCE LPE9403 firmware below V4.0 HF0 and three more in the separate SINEMA Remote Connect Edge Client through V2.1. The researchers said several of the bugs can be chained, turning limited access into root-level control of the edge device.

The chain matters because the SCALANCE LPE9403 sits between plant networks and upstream systems: Nozomi showed paths to alter telemetry sent to SCADA or visualization systems, suppress alarms, and in one case use the remote-connect side to run commands on connected SCALANCE devices and move laterally across OT networks. In plain terms, fixing only the box may leave the client path open.

For plants that use Siemens edge gear for remote access or data aggregation, the exposure is not just local to one appliance. The lasting risk is a cross-network control path: a foothold in the access layer can still shape what operators see and what downstream systems receive if both components are not addressed.

CVEs in this update

9 CVEs

Across SCALANCE LPE9403, scalance lpe9403 firmware.

0 critical · 3 high · 6 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2025-40582 · 7.8 HIGH

Highest EPSS: CVE-2025-40575 · 0.46%

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-21

Editions

Related stories