VDB

ICSA-22-167-12

ICSA-22-167-12 PUBLISHED CVSS 8.800000190734863 HIGH

Siemens has been made aware of a default password leakage in the internet affecting the component Shared HIS (SHHIS) used in Spectrum Power systems. The products listed below are affected by this default password leakage. This could allow an attacker to access the component Shared HIS of those products with administrative privileges by using an account with default credentials. Siemens offers configuration recommendations for the affected products in order to mitigate the issue.

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
Spectrum Power 4
Spectrum Power MGMS
Spectrum Power 7

Timeline

  • Jun 14, 2022 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›