First published: Tue Jan 11 2022(Updated: )
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens COMOS | <=10.2 | |
Siemens COMOS | >=10.3<10.3.3.3 | |
Siemens COMOS | =10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-37198.
The severity of CVE-2021-37198 is high with a severity value of 8.8.
COMOS V10.2 (All versions if web components are used), COMOS V10.3 (All versions < V10.3.3.3 if web components are used), COMOS V10.4 (All versions < V10.4.1 if web components are used).
The COMOS Web component of COMOS uses a flawed implementation, leading to a vulnerability in versions mentioned.
Implement the necessary security patches or updates provided by Siemens.