Siemens Spectrum Power 4 Database Credential Extraction Vulnerability

Vulnerability

A vulnerability exists in Siemens Spectrum Power 4, all versions prior to 4.70 SP12 Update 2, allowing the extraction of database credentials through a world-readable credential file. This exposure enables an attacker to connect to the database as a privileged application user and execute system commands via the database.

Impact

Exploitation of this vulnerability allows for unauthorized access to the database with elevated privileges, enabling the execution of system commands through the database interface.

Remediation

Users are advised to update to Siemens Spectrum Power 4 version 4.70 SP12 Update 2 or later. For guidance on applying the update, refer to the general security recommendations provided by Siemens.

Added: Nov 11, 2025, 9:39 PM
Updated: Nov 11, 2025, 9:39 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.