First published: Wed Apr 17 2019(Updated: )
A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the web server on port 80/TCP or 443/TCP could execute system commands with administrative privileges. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises confidentiality, integrity or availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Spectrum Power 4 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-6579.
The severity of CVE-2019-6579 is critical with a severity value of 9.8.
The affected software of CVE-2019-6579 is Siemens Spectrum Power 4.
This vulnerability can be exploited by an unauthenticated attacker with network access to the web server on port 80/TCP or 443/TCP, allowing them to execute system commands with administrative privileges.
Yes, you can find references for CVE-2019-6579 at the following URLs: http://www.securityfocus.com/bid/107830, https://cert-portal.siemens.com/productcert/pdf/ssa-324467.pdf.