First published: Tue Jan 11 2022(Updated: )
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens COMOS | <=10.2 | |
Siemens COMOS | >=10.3<10.3.3.3 | |
Siemens COMOS | =10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-37197 is high with a score of 8.8.
COMOS V10.2, COMOS V10.3 (versions < V10.3.3.3), and COMOS V10.4 (versions < V10.4.1) if web components are used.
The COMOS Web component of COMOS is vulnerable to SQL injection.
Apply the necessary patches or updates provided by Siemens to fix CVE-2021-37197 in COMOS.
More information about CVE-2021-37197 can be found at the Siemens CERT Portal: https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf