CVE-2013-4943
published 2013-08-09CVE-2013-4943: The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileges and…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.43%
34.8th percentile
The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileges and bypass intended database-operation restrictions by leveraging COMOS project access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | comos | — | — |
| siemens | comos | — | — |
| siemens | comos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gq85-v9q8-hp6f: The client application in Siemens COMOS before 9
ghsa_unreviewed·2022-05-17
CVE-2013-4943 [HIGH] GHSA-gq85-v9q8-hp6f: The client application in Siemens COMOS before 9
The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileges and bypass intended database-operation restrictions by leveraging COMOS project access.
CISA ICS
Siemens COMOS Privilege Escalation Vulnerability
cisa_ics·2013-08-21
Siemens COMOS Privilege Escalation Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS Privilege Escalation Vulnerability
Last RevisedAugust 21, 2013
Alert CodeICSA-13-233-01
## OVERVIEW
Siemens has notified ICS-CERT of a privilege escalation vulnerability in the Siemens COMOS database application. Siemens has produced a patch that mitigates this vulnerability.
## AFFECTED PRODUCTS
The following Siemens COMOS versions are affected:
- All COMOS versions prior to 9.1
- COMOS 9.1: all versions prior to LyraUpdate458 (Update 458)
- COMOS 9.2: all versions prior to V092_Upd06_Patch037 (9.2.0.6.37)
- COMOS 10.0: all versions prior to V100_SP03_Patch0
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-08-09
Published