CVE-2013-3927
published 2013-06-18CVE-2013-3927: Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write…
PriorityP414medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.36%
28.3th percentile
Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | comos | — | — |
| siemens | comos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mcx-8mcx-5rf8: Unspecified vulnerability in the client library in Siemens COMOS 9
ghsa_unreviewed·2022-05-17
CVE-2013-3927 [MEDIUM] GHSA-2mcx-8mcx-5rf8: Unspecified vulnerability in the client library in Siemens COMOS 9
Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.
CISA ICS
Siemens COMOS Permissions, Privileges, and Access Controls
cisa_ics·2013-06-21
Siemens COMOS Permissions, Privileges, and Access Controls
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS Permissions, Privileges, and Access Controls
Last RevisedJune 21, 2013
Alert CodeICSA-13-169-03
## OVERVIEW
This advisory provides mitigation details for vulnerabilities that impact the Siemens COMOS database system.
Siemens has identified a permissions, privileges, and access controls vulnerability in the Siemens COMOS database system. Siemens has produced software updates that mitigate this vulnerability. Siemens has tested the updates to validate that they resolve the vulnerability.
## AFFECTED PRODUCTS
The following Siemens COMOS Versions 9.2 and 10.0 are af
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-06-18
Published