First published: Wed Sep 09 2020(Updated: )
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Spectrum Power 4 | <4.70 | |
Siemens Spectrum Power 4 | =4.70 | |
Siemens Spectrum Power 4 | =4.70-sp7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15790 is a vulnerability identified in Spectrum Power 4 (All versions < V4.70 SP8) that could be susceptible to a directory listing attack if configured insecurely.
CVE-2020-15790 has a severity rating of medium with a CVSS score of 5.3.
All versions of Siemens Spectrum Power 4 below V4.70 SP8 are affected by CVE-2020-15790, including 4.70 and 4.70-sp7.
Ensure that the web server configuration in Spectrum Power 4 is secure to prevent a directory listing attack. Update to V4.70 SP8 or newer versions of the software.
You can find more information about CVE-2020-15790 in the Siemens ProductCERT advisory document available at the following link: [Siemens ProductCERT advisory document](https://cert-portal.siemens.com/productcert/pdf/ssa-568969.pdf).