CVE-2022-26476
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with default credentials. A successful exploitation could allow the attacker to access the component Shared HIS with administrative privileges.
Se ha identificado una vulnerabilidad en Spectrum Power 4 (Todas las versiones que usan HIS compartido), Spectrum Power 7 (Todas las versiones que usan HIS compartido), Spectrum Power MGMS (Todas las versiones que usan HIS compartido). Un atacante no autenticado podría entrar en el componente Shared HIS usado en los sistemas Spectrum Power usando una cuenta con credenciales por defecto. Una explotación con éxito podría permitir al atacante acceder al componente Shared HIS con privilegios administrativos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-04 CVE Reserved
- 2022-06-14 CVE Published
- 2023-11-25 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-388239.pdf | 2022-06-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Spectrum Power 4 Search vendor "Siemens" for product "Spectrum Power 4" | - | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Spectrum Power 7 Search vendor "Siemens" for product "Spectrum Power 7" | - | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Spectrum Power Microgrid Management System Search vendor "Siemens" for product "Spectrum Power Microgrid Management System" | - | - |
Affected
|