VulnerabilityModified
CVE-2012-3009
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.
HIGH 8.5EPSS 2.15%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.
- CVSS 2.0
- 8.5 HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- siemens/comos
- Source
- ics-cert@hq.dhs.gov
References
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-312568.pdfVendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-227-01.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-312568.pdfVendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-227-01.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.