CVE-2023-38557: Siemens Spectrum Power 7
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
Affected products
- Siemens Spectrum Power 7: before 23q3 (fixed in 23q3)
Published 2023-09-14. Last modified 2026-06-17.