Siemens Spectrum Power 4
cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*
- < V4.70 SP12 Update 2
A vulnerability exists in Siemens Spectrum Power 4, all versions prior to 4.70 SP12 Update 2, allowing the extraction of database credentials through a world-readable credential file. This exposure enables an attacker to connect to the database as a privileged application user and execute system commands via the database.
Exploitation of this vulnerability allows for unauthorized access to the database with elevated privileges, enabling the execution of system commands through the database interface.
Users are advised to update to Siemens Spectrum Power 4 version 4.70 SP12 Update 2 or later. For guidance on applying the update, refer to the general security recommendations provided by Siemens.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.