Siemens Spectrum Power 5
Siemens Spectrum Power 5 contains a reflected cross-site scripting (XSS) vulnerability in the web interface (CWE-80). An attacker could craft a malicious link that, when clicked by a logged-in operator, executes arbitrary JavaScript in the browser session. This could allow unauthorized access to grid monitoring data or control functions. The vulnerability affects all versions prior to 5.50_HF02. No security update is currently available; vendors are recommended to implement network controls and operational resilience measures per grid regulations.
- User interaction required: operator must click a malicious link
- Network access to Spectrum Power 5 web interface (typically port 80/443 on internal network)
- Operator must be logged into the application at time of click
Patching may require device reboot — plan for process interruption
/api/v1/advisories/2cc02171-4bbb-4d41-aac0-9b44de835aedGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.