A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-568969.pdf | vendor advisory |