| CVE-2023-46601 | | 0.00 | — | 0.00 | | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to. |
| CVE-2023-43505 | | 0.00 | — | 0.00 | | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to. |
| CVE-2023-43504 | | 0.00 | — | 0.00 | | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition. |
| CVE-2023-43503 | | 0.00 | — | 0.00 | | Nov 14, 2023 | A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive information such as user and project information in cleartext via UDP. |
| CVE-2013-6840 | | 0.00 | — | 0.00 | | Dec 10, 2013 | Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors. |
| CVE-2013-4943 | | 0.00 | — | 0.00 | | Aug 9, 2013 | The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileges and bypass intended database-operation restrictions by leveraging COMOS project access. |
| CVE-2013-3927 | | 0.00 | — | 0.00 | | Jun 18, 2013 | Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access. |
| CVE-2012-3009 | | 0.00 | — | 0.00 | | Aug 16, 2012 | Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls. |