PT-2025-46533 · Schneider Electric · Spectrum Power

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2024-32008

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spectrum Power versions prior to 4.70 SP12 Update 2
Description The application contains a flaw that allows local privilege escalation. An exposed debug interface on localhost enables any local user to gain code execution as an administrative application user.
Recommendations Update to version 4.70 SP12 Update 2 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-14353
CVE-2024-32008

Affected Products

Spectrum Power