PT-2019-2035 · Siemens · Spectrum Power 4
Published
2019-04-09
·
Updated
2020-10-16
·
CVE-2019-6579
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Spectrum Power 4 (with Web Office Portal) (affected versions not specified)
Description
A security issue has been identified that allows an attacker with network access to the web server on port 80/TCP or 443/TCP to execute system commands with administrative privileges. This issue can be exploited by an unauthenticated attacker without requiring any user interaction, potentially compromising the confidentiality, integrity, or availability of the targeted system. The issue is related to input control. At the time of reporting, no public exploitation of this issue was known.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spectrum Power 4