High severity8.8NVD Advisory· Published Jun 14, 2022· Updated Jun 17, 2026
CVE-2022-26476
CVE-2022-26476
Description
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum Power systems by using an account with default credentials. A successful exploitation could allow the attacker to access the component Shared HIS with administrative privileges.
Affected products
8- Range: All versions using Shared HIS
All versions using Shared HIS+ 4 more
- (no CPE)range: All versions using Shared HIS
- cpe:2.3:a:siemens:spectrum_power_4:-:*:*:*:*:*:*:*
- (no CPE)range: All versions using Shared HIS
- (no CPE)range: All versions using Shared HIS
- (no CPE)range: All versions using Shared HIS
- cpe:2.3:a:siemens:spectrum_power_7:-:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:spectrum_power_microgrid_management_system:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-388239.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.