CVE-2024-32010

7.8

Siemens · Spectrum Power 4

A vulnerability in Siemens Spectrum Power 4 allows local, low-privileged attackers to extract database credentials from a world-readable file, leading to full database control and system command execution.

Executive summary

A critical vulnerability in Siemens Spectrum Power 4 allows authenticated local attackers to achieve system command execution via exposed database credentials.

Vulnerability

The application is susceptible to an incorrect permission assignment (CWE-732) where a credential file is world-readable. An authenticated local user with low privileges can access this file to obtain administrative database credentials and subsequently execute arbitrary system commands.

Business impact

Successful exploitation poses a severe risk to operational integrity, as it grants an attacker full control over the database and the ability to execute system commands. Given the CVSS score of 7.8, this vulnerability represents a high risk for unauthorized access, potential data manipulation, and full system compromise within the affected environment.

Remediation

Immediate Action: Update Siemens Spectrum Power 4 to version V4.70 SP12 Update 2 or later as specified in the vendor advisory.

Proactive Monitoring: Audit local file system permissions for sensitive configuration files and monitor database access logs for unusual administrative activity or unexpected system command execution.

Compensating Controls: Restrict local system access to authorized personnel only and implement robust endpoint detection and response tools to identify unauthorized file access or anomalous process spawning.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw necessitates immediate attention, particularly in environments where local security boundaries are critical. Administrators must prioritize applying the provided patch to remediate the insecure file permissions and prevent potential privilege escalation. Failure to update leaves the system vulnerable to any local attacker capable of reading the exposed credential file.

More Siemens CVEs

Sources