CVE-2021-37196
MEDIUMSiemens COMOS Web < 10.2, 10.3 < 10.3.3.3, 10.4 < 10.4.1 - Path Traversal via Archive Extraction
Title source: llmDescription
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.3 (All versions >= V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS unpacks specially crafted archive files to relative paths. This vulnerability could allow an attacker to store files in any folder accessible by the COMOS Web webservice.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf
Scores
CVSS v3
6.5
EPSS
0.0034
EPSS Percentile
56.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
CWE-23
Status
published
Products (2)
siemens/comos
10.4
siemens/comos
< 10.2
Published
Jan 11, 2022
Tracked Since
Feb 18, 2026