Description
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
Scores
CVSS v3
5.5
EPSS
0.0027
EPSS Percentile
18.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-93
Status
published
Products (3)
Subnet Solutions/PowerSYSTEM Center 2020
< 5.28.x
Subnet Solutions/PowerSYSTEM Center 2024
6.0.x - 6.1.x
Subnet Solutions/PowerSYSTEM Center 2026
7.0.x
Published
May 12, 2026
Tracked Since
May 13, 2026