Subnet Solutions PowerSYSTEM Center
cpe:2.3:a:subnet:powersystem_center:*:*:*:*:*:*:*
- <= 5.28.x
- >= 5.8.x, <= 5.28.x
- >= 5.11.x, <= 5.28.x
- >= 6.0.x, <= 6.1.x
- 7.0.x
A CRLF injection vulnerability has been identified in the email notification service of Subnet Solutions PowerSYSTEM Center. This issue arises when the application uses SMTPS for communication. The vulnerability affects PowerSYSTEM Center versions 2020 through 5.28.x, as well as 2024 versions 6.0.x to 6.1.x and 2026 version 7.0.x.
Exploitation of this vulnerability could allow an authenticated attacker to inject carriage return and line feed characters, potentially leading to header manipulation or injection attacks.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.