CVE-2024-32008
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.12%
- CWE
- CWE-648
- Published
- 2025-11-11
- Last modified
- 2026-03-13
Affected products
- Siemens Spectrum Power 4
Weakness type
Related vulnerabilities
- CVE-2026-63727 — Anchore Enterprise Privilege Escalation via User Management API
- CVE-2026-54424 — An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a...
- CVE-2026-11877 — Missing Authorization Vulnerability in OpenText Access Manager
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-41225 — iControl REST vulnerability
- CVE-2026-41386 — OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
- CVE-2026-41329 — OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
- CVE-2026-35669 — OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope