CVE-2023-43505: Critical severity comos vulnerability
Published Nov 14, 2023
·Updated
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
Affected Software
1 affected component
Siemens COMOS
Event History
Nov 14, 2023
CVE Published
11:03 AM
Data Sourced
11:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-43505?
The severity of CVE-2023-43505 is critical with a CVSS score of 9.6.
2
How does CVE-2023-43505 affect COMOS?
CVE-2023-43505 affects all versions of COMOS by exposing a vulnerability in SMB shares, which can allow unauthorized access to files.
3
What is the CWE ID for CVE-2023-43505?
The CWE ID for CVE-2023-43505 is 284.
4
Is there a fix available for CVE-2023-43505?
Yes, Siemens has provided a fix for CVE-2023-43505. Please refer to the provided reference for more information.
5
Where can I find more information about CVE-2023-43505?
You can find more information about CVE-2023-43505 in the reference provided: https://cert-portal.siemens.com/productcert/pdf/ssa-137900.pdf