siemens spectrum-power-4 CVE-2022-26476 vulnerability in Siemens Products
Published on June 14, 2022

A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with default credentials. A successful exploitation could allow the attacker to access the component Shared HIS with administrative privileges.

NVD

Weakness Type

Use of Hard-coded Credentials

The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.


Products Associated with CVE-2022-26476

Want to know whenever a new CVE is published for Siemens products? stack.watch will email you.

 
 
 

Affected Versions

Siemens Spectrum Power 4: Siemens Spectrum Power 7: Siemens Spectrum Power MGMS:

Exploit Probability

EPSS
0.13%
Percentile
32.07%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.