OTPulse

Cross-Site Scripting Vulnerability in Spectrum Power 4

Monitor5.4SSA-831168Feb 8, 2022
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A Cross-Site Scripting (XSS) vulnerability exists in the integrated web application "Online Help" feature of Spectrum Power 4 versions prior to 4.70 SP9 Security Patch 1. The vulnerability allows injection of malicious scripts that execute in users' browsers when they interact with affected help pages.

What this means
What could happen
An attacker could inject malicious code into the web-based Online Help that would run in the browser of operators or engineers, allowing the attacker to steal session credentials or manipulate displayed information that operators rely on for control decisions.
Who's at risk
Electric utility operators and engineers at power generation and distribution facilities who use Spectrum Power 4 for monitoring and control. Anyone with browser access to the Spectrum Power 4 web interface, particularly those who consult Online Help documentation during operations.
How it could be exploited
An attacker would craft a malicious link or embed XSS payload in the Online Help feature of Spectrum Power 4. When an operator clicks the link or accesses the help page, the injected code runs in their browser without authentication, potentially capturing their session token or tricking them into providing credentials.
Prerequisites
  • User must click a malicious link or visit a crafted URL within Spectrum Power 4 Online Help
  • No special credentials required for the XSS attack itself, but operators typically have valid system access
remotely exploitablelow complexityrequires user interaction
Exploitability
Low exploit probability (EPSS 0.3%)
Affected products (1)
ProductAffected VersionsFix Status
Spectrum Power 4< V4.70 SP9 Security Patch 14.70 SP9 Security Patch 1
Remediation & Mitigation
0/2
Do now
0/1
HARDENINGRestrict network access to the Spectrum Power 4 web interface to authorized users and machines only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Spectrum Power 4 to version 4.70 SP9 Security Patch 1 or later
↑↓ Navigate · Esc Close
API: /api/v1/advisories/324e3954-2ca6-4324-a3d5-1951e1f472b7