CVE-2023-46601

CRITICAL

Siemens COMOS - Improper Access Control in SQL Server Connection

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.

References (1)

Core 1

Scores

CVSS v3 9.6
EPSS 0.0019
EPSS Percentile 40.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
siemens/comos
Published Nov 14, 2023
Tracked Since Feb 18, 2026