CVE-2021-37194

HIGH

Siemens Comos < 10.3.3.3 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS allows to upload and store arbitrary files at the webserver. This could allow an attacker to store malicious files.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (2)
siemens/comos 10.2
siemens/comos 10.3 - 10.3.3.3
Published Feb 09, 2022
Tracked Since Feb 18, 2026