CVE-2024-32008: High severity Siemens Spectrum Power 4 vulnerability
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Spectrum Power 4to a version that resolves this vulnerability.Fixed in V4.70 SP12 Update 2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32008?
CVE-2024-32008 is classified as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2024-32008?
To fix CVE-2024-32008, upgrade to Spectrum Power 4 version 4.70 SP12 Update 2 or later.
Who is affected by CVE-2024-32008?
All users of Spectrum Power 4 versions prior to 4.70 SP12 Update 2 are affected by CVE-2024-32008.
What type of vulnerability is CVE-2024-32008?
CVE-2024-32008 is a local privilege escalation vulnerability due to an exposed debug interface.
What can an attacker achieve with CVE-2024-32008?
An attacker can gain code execution as an administrative user on systems running affected versions of Spectrum Power 4.