CVE-2023-38557: Siemens Spectrum Power 7

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

Affected products

  • Siemens Spectrum Power 7: before 23q3 (fixed in 23q3)

Published 2023-09-14. Last modified 2026-06-17.