Siemens Spectrum Power 4 Database Modification Vulnerability Leading to Privilege Escalation

Vulnerability

A vulnerability exists in Siemens Spectrum Power 4, all versions prior to 4.70 SP12 Update 2, allowing unauthorized alteration of the local database that stores application credentials. This flaw enables an attacker to gain administrative privileges within the application.

Impact

Exploitation of this vulnerability allows for unauthorized modification of application credentials, leading to elevated administrative privileges within the application.

Remediation

Users are advised to update Siemens Spectrum Power 4 to version 4.70 SP12 Update 2 or later. Siemens recommends validating any security update before application and supervising the update process by trained staff. For additional guidance, consult the Siemens ProductCERT.

Added: Nov 11, 2025, 9:38 PM
Updated: Nov 11, 2025, 9:38 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
5.0
exploitability
4.9
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.