Siemens Spectrum Power 4
cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*
- < V4.70 SP12 Update 2
A local privilege escalation vulnerability has been identified in Siemens Spectrum Power 4, affecting all versions prior to 4.70 SP12 Update 2. The vulnerability arises from an exposed debug interface on localhost, which allows any local user to execute code as an administrative application user.
Exploitation of this vulnerability allows local users to gain administrative privileges within the application and execute code as an administrative user.
Users are advised to update to Siemens Spectrum Power 4 version 4.70 SP12 Update 2 or later. For guidance on applying the update, refer to the general security recommendations provided by Siemens.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.