CVE-2021-37198

Severity
8.8HIGH
EPSS
0.1%
top 65.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateFeb 10

Description

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDsiemens/comos10.310.3.3.3+2
CVEListV5siemens/comos_v10.2All versions only if web components are used
CVEListV5siemens/comos_v10.3All versions < V10.3.3.3 only if web components are used
CVEListV5siemens/comos_v10.4All versions < V10.4.1 only if web components are used

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4348-cfw6-3v28: A vulnerability has been identified in COMOS (All versions < V102022-02-10
CVEList
CVE-2021-37198: A vulnerability has been identified in COMOS V102022-01-11