PT-2025-46534 · Schneider Electric · Spectrum Power

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2024-32009

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spectrum Power versions prior to 4.70 SP12 Update 2
Description The application is susceptible to a local privilege escalation. Incorrectly configured permissions on a binary allow a local attacker to obtain administrative privileges.
Recommendations Update to version 4.70 SP12 Update 2 or later.

Fix

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-14351
CVE-2024-32009

Affected Products

Spectrum Power