CVE-2025-27397

CVSS 3.1 Score 3.8 of 10 (low)

Details

Published Mar 11, 2025
CWE ID 22

Summary

CVE-2025-27397 is a vulnerability affecting SCALANCE LPE9403 devices (6GK5998-3GS00-2AC2), versions prior to V4.0. The issue lies in the devices' failure to restrict user-controlled paths for log files, allowing authenticated remote attackers with high privileges to read and write arbitrary files if the malicious path ends with the string "log". This could potentially lead to serious security breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share