CVE-2024-32009
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-11
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | spectrum_power | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Spectrum Power 4 versions prior to V4.70 SP12 Update 2. It is a local privilege escalation issue caused by incorrectly set permissions on a binary, which allows any local attacker to gain administrative privileges on the affected system.
How can this vulnerability impact me? :
An attacker with local access to the system can exploit this vulnerability to escalate their privileges to administrative level. This can lead to full control over the system, potentially allowing the attacker to modify, delete, or steal sensitive data, disrupt system operations, or install malicious software.