📦 Comos

by Siemens

🔍 What is Comos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-43504

CRITICAL CVSS 9.6 Nov 14, 2023

A buffer overflow vulnerability in COMOS's Ptmcast executable allows attackers to execute arbitrary code or cause denial of service. This affects all COMOS versions before V10.4.4. Attackers could pot...

CVE-2023-24482

CRITICAL CVSS 10.0 Feb 14, 2023

This CVE describes a critical buffer overflow vulnerability in COMOS software's cache validation service. Attackers can exploit this Structured Exception Handler (SEH) based overflow to execute arbitr...

CVE-2021-45046

CRITICAL CVSS 9.0 Dec 14, 2021

CVE-2021-45046 is an incomplete fix for the Log4Shell vulnerability (CVE-2021-44228) in Apache Log4j 2.15.0 that allows attackers to execute arbitrary code via JNDI lookups in certain non-default logg...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2021-37197

HIGH CVSS 8.8 Jan 11, 2022

This vulnerability allows SQL injection attacks in Siemens COMOS web components, enabling attackers to execute arbitrary SQL statements. Affected systems include COMOS V10.2 (all versions with web com...

CVE-2021-32944

HIGH CVSS 7.8 Jun 17, 2021

This vulnerability allows attackers to execute arbitrary code or cause denial-of-service by exploiting a use-after-free memory corruption flaw in Siemens Drawings SDK when processing malicious DGN fil...

CVE-2021-32950

HIGH CVSS 7.1 Jun 17, 2021

This vulnerability allows attackers to cause denial-of-service or read sensitive memory information by exploiting an out-of-bounds read issue in the Drawings SDK when parsing malicious DXF files. It a...

CVE-2021-32938

HIGH CVSS 7.1 Jun 17, 2021

This vulnerability in Drawings SDK allows attackers to read sensitive information from memory or cause denial-of-service by exploiting improper validation of DWG file data. All versions prior to 2022....