Siemens Comos是德国西门子(Siemens)公司的一个工厂工程软件解决方案。用于过程工业。 Siemens COMOS Web 存在跨站脚本漏洞,该漏洞源于 COMOS 的 COMOS Web 组件接受任意代码作为任务的附件。 这可能允许攻击者注入在加载附件时执行的恶意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Siemens | COMOS V10.2 | All versions only if web components are used | - |
|
| Siemens | COMOS V10.3 | All versions < V10.3.3.3 only if web components are used | - |
|
| Siemens | COMOS V10.4 | All versions < V10.4.1 only if web components are used | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-45460 | Siemens Sicam Pq Analyzer 代码问题漏洞 | |
| CVE-2021-45033 | Siemens SICAM A8000 CP-8000 信任管理问题漏洞 | |
| CVE-2021-45034 | Siemens SICAM A8000 CP-8000 日志信息泄露漏洞 | |
| CVE-2021-41769 | Siemens SIPROTEC 5 输入验证错误漏洞 | |
| CVE-2021-37198 | Siemens Comos 跨站请求伪造漏洞 | |
| CVE-2021-37197 | Siemens Comos SQL注入漏洞 | |
| CVE-2021-37196 | Siemens Comos 路径遍历漏洞 |
No comments yet