CVE-2012-3009
published 2012-08-16CVE-2012-3009: Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database…
PriorityP339high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
2.15%
80.0th percentile
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | comos | <= 9.1 | — |
| siemens | comos | — | — |
| siemens | comos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS Database Privilege Escalation Vulnerability
cisa_ics·2013-05-07
Siemens COMOS Database Privilege Escalation Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS Database Privilege Escalation Vulnerability
Last RevisedMay 07, 2013
Alert CodeICSA-12-227-01
## Overview
Siemens has reported a privilege escalation vulnerability in the Siemens COMOS database application. Siemens has produced an update that fixes this vulnerability. This vulnerability could be exploited remotely.
## Affected Products
Siemens reports that the vulnerability affects the following versions of COMOS:
- all versions earlier than Version 9.1,
- Version 9.1: Patch 412 and earlier,
- Version 9.2: Update 3 Patch 022 and earlier, and
- Version 10: Pat
GHSA
GHSA-jj22-cwv6-836v: Siemens COMOS before 9
ghsa_unreviewed·2022-05-17
CVE-2012-3009 [HIGH] GHSA-jj22-cwv6-836v: Siemens COMOS before 9
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-312568.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-227-01.pdfhttp://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-312568.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-227-01.pdf
2012-08-16
Published