Home
MEDIUM: 5.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NMEDIUM: 5.5 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
Any version
affected
Default status
unaffected
6.0.x (custom)
affected
Default status
unaffected
7.0.x
affected
Description
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
Problem types
CWE-93 Improper neutralization of CRLF sequences ('CRLF injection')
Product status
Any version
6.0.x (custom)
7.0.x
Credits
Kelly Stich of Subnet Solutions Inc. reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-132-02
github.com/...p/csaf_files/OT/white/2026/icsa-26-132-02.json