A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spectrum_power_4 | Siemens | * | 4.70 (excluding) |
Spectrum_power_4 | Siemens | 4.70 (including) | 4.70 (including) |
Spectrum_power_4 | Siemens | 4.70-sp7 (including) | 4.70-sp7 (including) |