First published: Tue Jun 14 2022(Updated: )
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with default credentials. A successful exploitation could allow the attacker to access the component Shared HIS with administrative privileges.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Spectrum Power 4 | ||
Siemens Spectrum Power 7 | ||
Siemens Spectrum Power Microgrid Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26476 is a vulnerability identified in Siemens Spectrum Power 4, Spectrum Power 7, and Spectrum Power MGMS, allowing unauthenticated attackers to log into the component Shared HIS.
CVE-2022-26476 has a severity rating of 8.8 (high).
CVE-2022-26476 affects Siemens Spectrum Power 4, Spectrum Power 7, and Spectrum Power MGMS (all versions using Shared HIS).
An unauthenticated attacker can exploit CVE-2022-26476 by logging into the Shared HIS component used in Siemens Spectrum Power systems.
Please refer to the reference link provided for information on available fixes for CVE-2022-26476.