CVE-2023-24482: Buffer Overflow
A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All versions < V10.4.0.0.31), COMOS V10.4.1.0 (All versions < V10.4.1.0.32), COMOS V10.4.2.0 (All versions < V10.4.2.0.25). Cache validation service in COMOS is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-24482.
What is the severity of CVE-2023-24482?
CVE-2023-24482 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2023-24482?
CVE-2023-24482 affects multiple versions of Siemens COMOS, including V10.2, V10.3.3.1, V10.3.3.2, V10.3.3.3, V10.3.3.4, V10.4.0.0, V10.4.1.0, and V10.4.2.0.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-24482?
CVE-2023-24482 is associated with CWE-119 and CWE-120.
Where can I find more information about CVE-2023-24482?
More information about CVE-2023-24482 can be found at https://cert-portal.siemens.com/productcert/pdf/ssa-693110.pdf.