← Retour aux CVEs
CVE-2022-26476
HIGH8.8
Description
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with default credentials. A successful exploitation could allow the attacker to access the component Shared HIS with administrative privileges.
Details CVE
Score CVSS v3.18.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie6/14/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
siemens:spectrum_power_4siemens:spectrum_power_7siemens:spectrum_power_microgrid_management_system
Faiblesses (CWE)
CWE-798CWE-798
References
https://cert-portal.siemens.com/productcert/pdf/ssa-388239.pdf(productcert@siemens.com)
https://cert-portal.siemens.com/productcert/pdf/ssa-388239.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.