{"id":11587,"date":"2026-01-30T15:10:38","date_gmt":"2026-01-30T14:10:38","guid":{"rendered":"https:\/\/limessecurity.ninja\/?p=11587"},"modified":"2026-03-10T09:01:12","modified_gmt":"2026-03-10T08:01:12","slug":"siemens-power-spectrum-vulnerability-cve-2024-32011","status":"publish","type":"post","link":"https:\/\/limessecurity.com\/de\/siemens-power-spectrum-vulnerability-cve-2024-32011\/","title":{"rendered":"Siemens Spectrum Power 4 &#8211; kritische Schwachstellen in SCADA- und Energiemanagementsystem entdeckt"},"content":{"rendered":"[vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Bei einem Pentest haben wir <strong>f\u00fcnf Schwachstellen in Siemens Spectrum Power 4 entdeckt<\/strong> \u2013 einem weit verbreiteten SCADA- und Energiemanagementsystem, das von \u00dcbertragungs- und Verteilungsnetzbetreibern weltweit eingesetzt wird. Die Schwachstellen erm\u00f6glichen sowohl lokale Privilegieneskalation als auch die Remote-Ausf\u00fchrung von Code als Anwendungsadministrator.<\/p>\n<p>Vorweg: Siemens hat zwischenzeitlich das Update 2 f\u00fcr V4.70 SP12 ver\u00f6ffentlicht, das die nachstehend beschriebenen Probleme behebt. Betreiber, die die betroffene Version von Siemens Spectrum Power 4 verwenden, sollten das Update gem\u00e4\u00df den Anweisungen von Siemens unbedingt installieren.[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<h2>Entdeckte Sicherheitsl\u00fccken<\/h2>\n[\/vc_column_text][divider line_type=&#8220;No Line&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;87&#8243; label_value=&#8220;8.7&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1769763535769{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; el_id=&#8220;orangePieChart&#8220; title=&#8220;CVSS v4.0 Score&#8220; units=&#8220;\/high&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441296-9&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Produkt:&#8220; text=&#8220;Siemens Spectrum Power 4&#8243; tab_id=&#8220;1769782441296-10&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441311-7&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Betroffene Versionen:&#8220; text=&#8220;Version 4.70 SP12 Update 2&#8243; tab_id=&#8220;1769782441312-9&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441317-5&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1769782441317-9&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-339694.html\" target=\"_blank\" rel=\"noopener\">CVE-2024-32011<\/a><\/p>\n[\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441332-10&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Gefunden von:&#8220; text=&#8220;Felix Eberstaller und Sixtus Leonhardsberger, Limes Security GmbH&#8220; tab_id=&#8220;1769782441333-0&#8243;][\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][nectar_btn size=&#8220;small&#8220; button_style=&#8220;regular&#8220; button_color_2=&#8220;Accent-Color&#8220; icon_family=&#8220;none&#8220; text=&#8220;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:L\/UI:N\/VC:H\/VI:H\/VA:H\/SC:N\/SI:N\/SA:N&#8220; url=&#8220;https:\/\/www.first.org\/cvss\/calculator\/4-0#CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:L\/UI:N\/VC:H\/VI:H\/VA:H\/SC:N\/SI:N\/SA:N&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Remote-Befehlsausf\u00fchrung \u00fcber eine \u00fcber das Netzwerk zug\u00e4ngliche Benutzeroberfl\u00e4che[\/vc_column_text][divider line_type=&#8220;Small Line&#8220; line_alignment=&#8220;center&#8220; line_thickness=&#8220;1&#8243; divider_color=&#8220;default&#8220;][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/2&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;85&#8243; label_value=&#8220;8.5&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1769763561805{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; title=&#8220;CVSS v4.0 Score&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441513-7&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1769782441514-4&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-339694.html\" target=\"_blank\" rel=\"noopener\">CVE-2024-32008<\/a><\/p>\n[\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<p style=\"text-align: center;\">Lokale Privilegieneskalation \u00fcber die Debug-Schnittstelle<\/p>\n[\/vc_column_text][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;10 px&#8220;][\/vc_column][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/2&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;85&#8243; label_value=&#8220;8.5&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1769763571760{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; title=&#8220;CVSS v4.0 Score&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441651-0&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1769782441652-5&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-339694.html\" target=\"_blank\" rel=\"noopener\">CVE-2024-32009<\/a><\/p>\n[\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<p style=\"text-align: center;\">Lokale Rechteausweitung \u00fcber fehlerhafte Bin\u00e4rkonfiguration<\/p>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/2&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;85&#8243; label_value=&#8220;8.5&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1769763583261{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; title=&#8220;CVSS v4.0 Score&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441819-7&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1769782441820-4&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-339694.html\" target=\"_blank\" rel=\"noopener\">CVE-2024-32010<\/a><\/p>\n[\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<p style=\"text-align: center;\">Extraktion von Anmeldedaten aus einer weltweit lesbaren Datei<\/p>\n[\/vc_column_text][\/vc_column][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/2&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;56&#8243; label_value=&#8220;5.6&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1769763593897{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; title=&#8220;CVSS v4.0 Score&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1769782441967-0&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1769782441967-3&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-339694.html\" target=\"_blank\" rel=\"noopener\">CVE-2024-32014<\/a><\/p>\n[\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<p style=\"text-align: center;\">Lokale Datenbankmanipulation<\/p>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;20px&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Detaillierte Schritte zur Ausn\u00fctzung der Schwachstelle halten wir zur\u00fcck, da viele Betreiber aktuell noch damit besch\u00e4ftigt sind, Ma\u00dfnahmen zu ergreifen. Es wird jedoch das allgemeine Angriffsmuster f\u00fcr CVE-2024-32011 bekanntgegeben.<\/p>\n<h2>Angriffsmuster: Kiosk-Escape mit unerwarteten Folgen<\/h2>\n<p>Spectrum Power 4 bietet Benutzern einen SCADA-Client f\u00fcr die Interaktion mit Netzmanagement-Anwendungen auf dem Server. Wie auch andere SCADA-Systeme, verwendet es X11 f\u00fcr die grafische Darstellung \u2013 entscheidend ist jedoch, dass diese Sitzungen serverseitig und nicht auf dem Client gerendert werden.<\/p>\n<p>\u00dcber die SCADA-Benutzeroberfl\u00e4che k\u00f6nnen Betreiber verschiedene Hilfsanwendungen wie PDF-Viewer oder -Editoren starten. Einige dieser Anwendungen bieten Funktionen zum Durchsuchen des lokalen Dateisystems oder zum Starten externer Programme. Ein Angreifer, der dies ausnutzt, kann die vorgesehene Anwendungsgrenze umgehen \u2013 beispielsweise durch \u00d6ffnen eines Dateibrowser-Dialogfelds, Navigieren zu einem Terminalemulator oder Nutzen einer Anwendung wie gvim \u2013, um Shell-Befehle auszuf\u00fchren.[\/vc_column_text][\/vc_column][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;7%&#8220; bottom_margin=&#8220;7%&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][image_with_animation image_url=&#8220;11591&#8243; image_size=&#8220;full&#8220; max_width=&#8220;100%&#8220; max_width_mobile=&#8220;default&#8220; animation_type=&#8220;entrance&#8220; animation=&#8220;None&#8220; animation_movement_type=&#8220;transform_y&#8220; hover_animation=&#8220;none&#8220; alignment=&#8220;center&#8220; border_radius=&#8220;none&#8220; box_shadow=&#8220;none&#8220; image_loading=&#8220;default&#8220;][\/vc_column][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]<strong>Das Hauptproblem: Aufgrund der serverseitigen X11-Architektur landet dieser Shell-Zugriff direkt auf dem Spectrum Power-Server selbst und nicht auf dem Client-Rechner des Benutzers.<\/strong><\/p>\n<p>Von diesem ersten Zugangspunkt aus kann ein Angreifer die lokalen Schwachstellen zur Rechteausweitung (CVE-2024-32008, CVE-2024-32009 oder CVE-2024-32010) miteinander verketten, um die vollst\u00e4ndige administrative Kontrolle \u00fcber den Server zu erlangen. Angesichts der Vernetzung von Spectrum Power-Implementierungen kann dies eine laterale Bewegung \u00fcber die gesamte Netzmanagement-Infrastruktur hinweg erm\u00f6glichen.[\/vc_column_text][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;15px&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<h2><strong>\u00dcber Spectrum Power 4<\/strong><\/h2>\n<p><em>Siemens Spectrum Power<\/em> ist ein Softwaresystem f\u00fcr die zuverl\u00e4ssige und sichere Betriebsf\u00fchrung von modernen Stromnetzen. Laut Siemens handelt es sich dabei um \u201edie weltweit f\u00fchrende L\u00f6sung\u201c. Die aktuelle Generation, Spectrum Power 7, ist in \u00fcber 1.300 Kontrollzentren in 90 L\u00e4ndern im Einsatz.<\/p>\n<p>Die CISA stuft Spectrum Power-Implementierungen in kritischen Infrastruktursektoren wie Energie, Chemie, kritische Fertigung, Lebensmittel und Landwirtschaft sowie Wasser- und Abwassersysteme ein (<a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-19-099-02\" target=\"_blank\" rel=\"noopener\">ICSA-19-099-02<\/a>).<\/p>\n<h3>Veraltet, aber noch in Produktion<\/h3>\n<p>Spectrum Power 4 ist der Vorg\u00e4nger der aktuellen Spectrum Power 7-Produktlinie. W\u00e4hrend Siemens SP7 aktiv f\u00fcr neue Implementierungen vermarktet \u2013 darunter ein k\u00fcrzlich abgeschlossener Gro\u00dfauftrag mit DB Energie f\u00fcr das deutsche Eisenbahnnetz \u2013, sind weltweit noch viele SP4-Installationen in Betrieb.<\/p>\n<p>Dies ist typisch f\u00fcr kritische Infrastrukturen. SCADA- und EMS-Upgrades sind komplexe, mehrj\u00e4hrige Projekte, die \u00fcberlicherweise folgende Merkmale aufweisen:<\/p>\n<ul>\n<li><strong>Anforderungen an die Verf\u00fcgbarkeit rund um die Uhr<\/strong> \u2013 Netze k\u00f6nnen f\u00fcr Migrationen nicht offline gehen<\/li>\n<li><strong>Regulatorische Anforderungen<\/strong> \u2013 neue Systeme erfordern eine umfassende Validierung<\/li>\n<li><strong>Integrationsabh\u00e4ngigkeiten<\/strong> \u2013 Verbindungen zu RTUs, Historien, Marktsystemen und Tools von Drittanbietern<\/li>\n<li><strong>Budgetzyklen<\/strong> \u2013 Investitionen in die Modernisierung von Steuerungssystemen konkurrieren mit anderen Netzinvestitionen<\/li>\n<\/ul>\n<p>Das Ergebnis ist eine lange Reihe von Altsystemen, die in der Produktion laufen, oft ein Jahrzehnt oder l\u00e4nger \u00fcber ihren vorgesehenen Lebenszyklus hinaus. Die Sicherheitsforschung zu diesen Systemen bleibt kritisch \u2013 Betreiber ben\u00f6tigen Informationen zu Schwachstellen und Patches, unabh\u00e4ngig davon, ob das Produkt noch aktiv verkauft wird.<\/p>\n<p>Diese Erkenntnis unterstreicht den noch immer hohen Wert von Produktbewertungen und warum regelm\u00e4\u00dfige Sicherheitsbewertungen von SCADA- und EMS-Produkten nach wie vor unerl\u00e4sslich sind.[\/vc_column_text][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;20 px&#8220;][\/vc_column][\/vc_row]\n","protected":false},"excerpt":{"rendered":"<p>[vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220;&#8230;<\/p>\n","protected":false},"author":5,"featured_media":14688,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[281],"tags":[],"class_list":{"0":"post-11587","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-advisories"},"_links":{"self":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts\/11587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/comments?post=11587"}],"version-history":[{"count":0,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts\/11587\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/media\/14688"}],"wp:attachment":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/media?parent=11587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/categories?post=11587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/tags?post=11587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}