Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-27409

CVSS 2.5 · Low EPSS 0.09% · P25
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-27409

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Siemens SCALANCE 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SCALANCE是德国西门子(Siemens)公司的一系列以太网交换机。可连接到工业控制系统 (ICS) 设备,包括可编程逻辑控制器 (PLC) 和人机界面 (HMI) 系统。 Siemens SCALANCE 存在路径遍历漏洞,该漏洞源于通过 mac 参数在 deviceinfo 二进制文件中发现路径遍历漏洞。这可能允许经过身份验证的攻击者访问受影响设备上的 SSH 接口,以读取任何名为address的文件内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SiemensSCALANCE LPE9403 All versions < V2.1 -

II. Public POCs for CVE-2023-27409

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-27409

登录查看更多情报信息。

Same Patch Batch · Siemens · 2023-05-09 · 15 CVEs total

CVE-2023-308999.9 CRITICALSiemens Siveillance Video Mobile Server 代码问题漏洞
CVE-2023-308989.9 CRITICALSiemens Siveillance Video Mobile Server 代码问题漏洞
CVE-2023-274079.9 CRITICALSiemens SCALANCE 命令注入漏洞
CVE-2023-309867.8 HIGHSiemens Solid Edge 缓冲区错误漏洞
CVE-2023-288327.2 HIGHSiemens SIMATIC Cloud Connect 命令注入漏洞
CVE-2023-291046.0 MEDIUMSiemens SIMATIC Cloud Connect 路径遍历漏洞
CVE-2023-291055.9 MEDIUMSiemens SIMATIC Cloud Connect安全漏洞
CVE-2023-291075.3 MEDIUMSiemens SIMATIC Cloud Connect 安全漏洞
CVE-2023-291065.3 MEDIUMSiemens SIMATIC Cloud Connect 信息泄露漏洞
CVE-2023-291034.3 MEDIUMSiemens SIMATIC Cloud Connect 安全漏洞
CVE-2023-291283.8 LOWSiemens SIMATIC Cloud Connect 路径遍历漏洞
CVE-2023-309853.3 LOWSiemens Solid Edge 缓冲区错误漏洞
CVE-2023-274083.3 LOWSiemens SCALANCE 安全漏洞
CVE-2023-274102.7 LOWSiemens SCALANCE 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-27409

No comments yet


Leave a comment