Vulnerabilities (CVE)

Filtered by vendor Siemens Subscribe
Filtered by product Comos
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43505 1 Siemens 1 Comos 2023-11-18 N/A 6.5 MEDIUM
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
CVE-2021-37196 1 Siemens 1 Comos 2022-04-30 3.5 LOW 6.5 MEDIUM
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.3 (All versions >= V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS unpacks specially crafted archive files to relative paths. This vulnerability could allow an attacker to store files in any folder accessible by the COMOS Web webservice.
CVE-2021-37195 1 Siemens 1 Comos 2022-04-29 2.6 LOW 6.1 MEDIUM
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS accepts arbitrary code as attachment to tasks. This could allow an attacker to inject malicious code that is executed when loading the attachment.