CVE-2024-32010 - Spectrum Power 4 Database Credential Extraction and Command Injection Vulnerability
CVE ID : CVE-2024-32010
Published : Nov. 11, 2025, 9:15 p.m. | 32 minutes ago
Description : A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands via the database.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Nov. 11, 2025, 9:15 p.m. | 32 minutes ago
Description : A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands via the database.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...