Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unknown
Any version before V4.70 SP12 Update 2
affected
Description
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.
Problem types
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Product status
Any version before V4.70 SP12 Update 2
References
cert-portal.siemens.com/productcert/html/ssa-339694.html