CVE-2021-37198: CSRF
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-37198.
What is the severity of CVE-2021-37198?
The severity of CVE-2021-37198 is high with a severity value of 8.8.
Which versions of COMOS are affected by CVE-2021-37198?
COMOS V10.2 (All versions if web components are used), COMOS V10.3 (All versions < V10.3.3.3 if web components are used), COMOS V10.4 (All versions < V10.4.1 if web components are used).
What is the vulnerability description of CVE-2021-37198?
The COMOS Web component of COMOS uses a flawed implementation, leading to a vulnerability in versions mentioned.
How can I fix the CVE-2021-37198 vulnerability?
Implement the necessary security patches or updates provided by Siemens.