CVE-2024-32010 is a high-severity vulnerability affecting all versions of Siemens Spectrum Power 4 prior to V4.70 SP12 Update 2. It allows for the extraction of database credentials from a world-readable file, enabling an authenticated local attacker to gain privileged access to the database and execute system commands. With a CVSS score of 7.8, this vulnerability has high confidentiality, integrity, and availability impacts, but requires local access and low privileges. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | Spectrum Power 4 | >= 0, < V4.70 SP12 Update 2CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.