VYPR
High severity8.8NVD Advisory· Published Jan 11, 2022· Updated Jun 17, 2026

CVE-2021-37198

CVE-2021-37198

Description

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks.

Affected products

7
  • cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*range: <=10.2
    • cpe:2.3:a:siemens:comos:10.4:*:*:*:*:*:*:*
    • (no CPE)
  • COMOS/COMOSllm-fuzzy
  • Siemens/COMOS V10.2v5
    Range: All versions only if web components are used
  • Siemens/COMOS V10.3v5
    Range: All versions < V10.3.3.3 only if web components are used
  • Siemens/COMOS V10.4v5
    Range: All versions < V10.4.1 only if web components are used

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.