Database Credential Exposure in Spectrum Power 4 by Siemens
CVE-2024-32010
8.5HIGH
What is CVE-2024-32010?
A vulnerability exists in Spectrum Power 4 that allows unauthorized access to database credentials through a world-readable credential file. This serious issue enables attackers to connect to the database as a privileged application user, granting them the ability to execute system commands within the database context. It highlights the importance of securing configuration files and access permissions to prevent unauthorized data extraction.
Affected Version(s)
Spectrum Power 4 0