A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.
History

Wed, 12 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens spectrum Power 4
Vendors & Products Siemens
Siemens spectrum Power 4

Tue, 11 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2025-11-11T20:20:18.134Z

Updated: 2025-11-12T21:09:08.910Z

Reserved: 2024-04-08T15:37:27.223Z

Link: CVE-2024-32011

cve-icon Vulnrichment

Updated: 2025-11-12T21:07:40.411Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T21:15:35.623

Modified: 2025-11-12T16:19:12.850

Link: CVE-2024-32011

cve-icon Redhat

No data.