In the second part of its research on security vulnerabilities in Siemens SCALANCE LPE9403 Local Processing Engine, researchers from Nozomi Networks Labs identified 12 vulnerabilities that affect devices running firmware below V4.0 HF0. Three additional flaws affect systems with the SINEMA Remote Connect Edge Client installed through version V2.1. Vulnerabilities include privilege escalation, path traversal, authentication bypass, command injection, buffer overflows, and memory-handling issues, with CVSS scores ranging from 5.3 to 8.5.
Nozomi identified that several of the vulnerabilities can be chained to obtain root-level control of the SCALANCE LPE9403, potentially allowing attackers to manipulate telemetry, suppress alarms, access operational information, or disrupt services. In one scenario, an attacker with limited access could exploit three vulnerabilities to escalate privileges and alter data sent to SCADA or visualization systems. In another instance, compromising a SINEMA Remote Connect server could enable command execution on connected SCALANCE LPE devices and facilitate lateral movement across multiple OT networks.
The researchers noted that “the impact of the identified vulnerabilities is strongly influenced by the role of the Siemens SCALANCE LPE9403 as an OT edge device and by the fact that several issues can be chained to achieve full system compromise. Multiple vulnerabilities allow attackers to move from limited access to root-level control of the SCALANCE LPE, significantly increasing the potential impact on industrial environments.”
The San Francisco, California-based vendor reported the findings responsibly to Siemens with technical reproduction details, then documented real-world exploitation scenarios and their OT environment impact. DCP (Discovery and Configuration Protocol) vulnerabilities are detailed in a separate technical analysis. Siemens analyzed and patched vulnerabilities and published an advisory that asset owners and operators must review and apply updates immediately, implement network segmentation, and monitor for vulnerable systems to reduce exposure.
“Our research looked at the Siemens SCALANCE LPE9403 Local Processing Engine (LPE), a rugged industrial ‘edge PC’ that’s installed in OT environments to run local apps and expose a set of services that help it integrate into plant networks,” according to the post. “Depending on how it’s deployed, it could be used as a data aggregator: pulling telemetry and operational signals from the OT network, then forwarding that data upstream to SCADA systems (and similar monitoring/control platforms).”
Users can also optionally install the SINEMA Remote Connect client on the SCALANCE LPE. SINEMA Remote Connect is Siemens’ remote-access solution, used to provide secure VPN-based connectivity so that authorized operators, system integrators, or maintenance teams can reach industrial assets without being physically on site. Since that client becomes part of the SIEMENS LPE software stack and can influence the device’s remote exposure, the SINEMA Remote Connect package was part of Nozomi’s research.
Nozomi Networks Labs identified nine vulnerabilities in Siemens SCALANCE LPE9403 devices running firmware versions lower than V4.0 HF0. The vulnerabilities include incorrect permission assignment for a critical resource, path traversal, use of an uninitialized value, NULL pointer dereference, out-of-bounds read and stack-based buffer overflow issues. The vulnerabilities are tracked as CVE-2025-40572 through CVE-2025-40580 and have CVSS scores ranging from 5.3 to 8.5.
The researchers also identified three vulnerabilities in SCALANCE LPE9403 devices with the SINEMA Remote Connect Edge Client installed through version V2.1. These vulnerabilities include authentication bypass using an alternate path or channel, improper neutralization of special elements used in an OS command, and cleartext transmission of sensi