CVE-2023-43505

CRITICAL

Siemens COMOS - Improper Access Control in SMB Shares

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.

References (1)

Core 1

Scores

CVSS v3 9.6
EPSS 0.0017
EPSS Percentile 37.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
siemens/comos
Published Nov 14, 2023
Tracked Since Feb 18, 2026