CVE-2013-6840
published 2013-12-10CVE-2013-6840: Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors.
PriorityP419medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.31%
22.8th percentile
Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | comos | — | — |
| siemens | comos | — | — |
| siemens | comos | — | — |
| siemens | comos | — | — |
| siemens | comos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS Privilege Escalation
cisa_ics·2018-08-29
Siemens COMOS Privilege Escalation
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS Privilege Escalation
Last RevisedAugust 29, 2018
Alert CodeICSA-13-347-01
## OVERVIEW
Siemens notified NCCIC/ICS-CERT of a privilege escalation vulnerability in the Siemens COMOS database application. An update has been produced by Siemens and is available to resolve the vulnerability.
The client application used for accessing the database system might allow authenticated Windows users to elevate their rights in regard to the database access over the COMOS graphical user interface.
## AFFECTED PRODUCTS
The following Siemens products are affected:
- All COMOS ve
GHSA
GHSA-xc76-crcf-v554: Siemens COMOS before 9
ghsa_unreviewed·2022-05-17
CVE-2013-6840 [MEDIUM] GHSA-xc76-crcf-v554: Siemens COMOS before 9
Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/56010http://www.securityfocus.com/bid/64153https://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-568732.pdfhttp://secunia.com/advisories/56010http://www.securityfocus.com/bid/64153https://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-568732.pdf
2013-12-10
Published