Siemens Spectrum Power CVE-2019-6579 Command Injection Vulnerability
BID:107830
CVE-2019-6579 |Info
Siemens Spectrum Power CVE-2019-6579 Command Injection Vulnerability
| Bugtraq ID: | 107830 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6579 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2019 12:00AM |
| Updated: | Apr 09 2019 12:00AM |
| Credit: | Applied Risk |
| Vulnerable: |
Siemens Spectrum Power 4.7 |
| Not Vulnerable: | |
Discussion
Siemens Spectrum Power CVE-2019-6579 Command Injection Vulnerability
Siemens Spectrum Power is prone to a remote command-injection vulnerability.
An attacker can exploit this issue to execute arbitrary commands with elevated administrative privileges; this may aid in further attacks.
Siemens Spectrum Power 4.7 with Web Office Portal is vulnerable; other versions may also be affected.
Siemens Spectrum Power is prone to a remote command-injection vulnerability.
An attacker can exploit this issue to execute arbitrary commands with elevated administrative privileges; this may aid in further attacks.
Siemens Spectrum Power 4.7 with Web Office Portal is vulnerable; other versions may also be affected.
Exploit / POC
Siemens Spectrum Power CVE-2019-6579 Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Siemens Spectrum Power CVE-2019-6579 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Siemens Spectrum Power CVE-2019-6579 Command Injection Vulnerability
References:
References:
- Siemens Homepage (Siemens)
- ICSA-19-099-02: Siemens Spectrum Power 4.7 (ICS CERT)
- SSA-324467: OS Command Injection in Spectrum Power 4.7 (Siemens)