CVE-2021-37194

HIGH

Siemens COMOS < V10.3.3.3, V10.4 < V10.4.1 - Unrestricted File Upload via Web Component

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS allows to upload and store arbitrary files at the webserver. This could allow an attacker to store malicious files.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf

Scores

CVSS v3 7.5
EPSS 0.0083
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (2)
siemens/comos 10.2
siemens/comos 10.3 - 10.3.3.3
Published Feb 09, 2022
Tracked Since Feb 18, 2026