PT-2019-2035 · Siemens · Spectrum Power 4
Publicado
2019-04-09
·
Atualizado
2020-10-16
·
CVE-2019-6579
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Spectrum Power 4 (with Web Office Portal) (affected versions not specified)
Description
A security issue has been identified that allows an attacker with network access to the web server on port 80/TCP or 443/TCP to execute system commands with administrative privileges. This issue can be exploited by an unauthenticated attacker without requiring any user interaction, potentially compromising the confidentiality, integrity, or availability of the targeted system. The issue is related to input control. At the time of reporting, no public exploitation of this issue was known.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Spectrum Power 4