Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
The vulnerability classified as CWE-287 (Missing Authentication for a Critical Function) means that specific functionality of the Loftware Spectrum application is accessible without requiring user authentication. An attacker can send a properly crafted network request directly to the vulnerable endpoint, bypassing access control mechanisms. Due to the network vector (AV:N) and the absence of user interaction requirement (UI:N) or privileges (PR:N), the attack can be conducted entirely remotely and without any prior permissions.
An attacker can gain unauthorized access to sensitive data, modify system content, and cause its unavailability, which corresponds to maximum impact on confidentiality, integrity, and availability (C:H/I:H/A:H).
Loftware Spectrum should be updated to version 4.6 HF14 or later according to the manufacturer's information available in the release notes: https://docs.loftware.com/spectrum-releasenotes/Content/Hotfix/4.6_HF14.htm
Loftware Spectrum in versions prior to 4.6 HF14
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLoftware Spectrum
APPLoftware4.6< 4.6
Related vulnerabilities
Loftware Spectrum — zakodowane na stałe hasło (Hard-coded Password)
Niebezpieczna deserializacja danych w Loftware Spectrum przed wersją 4.6 HF13
Loftware Spectrum — niezabezpieczony rejestr JMX umożliwia zdalny dostęp
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.