Advisory Name: SSA-339694: Multiple Vulnerabilities in Spectrum Power 4 Before v4.70 SP12 Security Patch 2 Affected Products: - Spectrum Power 4 - All versions < V4.70 SP12 Update 2 CVEs: - CVE-2024-32008: Local Privilege Escalation due to exposed debug interface on localhost. - CVSS v3.1: 7.8 - CVSS v4.0: 8.5 - CVE-2024-32009: Local Privilege Escalation due to wrongly set permissions on a binary. - CVSS v3.1: 7.8 - CVSS v4.0: 8.5 - CVE-2024-32010: Extraction of database credentials through a world-readable credentials file. - CVSS v3.1: 7.8 - CVSS v4.0: 8.5 - CVE-2024-32011: Arbitrary command execution via the user interface. - CVSS v3.1: 8.8 - CVSS v4.0: 8.7 - CVE-2024-32014: Alteration of the local database containing application credentials. - CVSS v3.1: 4.7 - CVSS v4.0: 5.6 Mitigations: - Update to V4.70 SP12 Update 2 or a later version - Follow security recommendations provided. Acknowledgments: - Vulnerabilities reported by Felix Eberstaller and Sixtus Leonhardsberger from Limes Security CVSS Scores: - CVSS v3.1 Base Score: 8.8 - CVSS v4.0 Base Score: 8.7