---
id: CVE-2024-32011
title: >-
  A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70
  SP12 Update 2)
summary: >-
  A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70
  SP12 Update 2). The affected application is vulnerable to run arbitrary
  commands via the user interface. This user interface can be used via the
  network and al…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-829
published: '2025-11-11'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-32011'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-339694.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.0039
epssPercentile: 0.30487
ingestedAt: '2026-09-26T21:38:01.489Z'
---

## Overview

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
