CVE-2024-32008
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-11
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | spectrum_power | 4.0 |
| siemens | spectrum_power | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-648 | The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Spectrum Power 4 versions prior to V4.70 SP12 Update 2. It is a local privilege escalation issue caused by an exposed debug interface accessible on the localhost. This flaw allows any local user to execute code with administrative application user privileges.
How can this vulnerability impact me? :
The vulnerability can allow a local user to gain administrative-level code execution within the affected application. This can lead to unauthorized control over the application, potentially compromising system integrity, confidentiality, and availability.