← Back to home
ICSA-12-227-01  ·  Published 2025-06-05  ·  View on CISA ICS-CERT ↗

Siemens COMOS Database Privilege Escalation Vulnerability

CVSS 8.5 HIGH

CVEs (1)

Remediations

  • For COMOS Versions 9.1, 9.2, and 10.0, Siemens recommends installing the corresponding patches as soon as possible: Version 9.1 Patch 413, Version 9.2 Update 03 Patch 023, and Version V10 Patch 005. These software updates are available at Siemens customer support. For earlier versions, Siemens recommends upgrading to a newer version. (https://cert-portal.siemens.com/productcert/pdf/ssa-312568.pdf)

Affected Vendors

Siemens

Affected Products (4)

Siemens · COMOS <9.1
Siemens · COMOS Version 9.1 <=Patch_412
Siemens · COMOS Version 9.2 <=Update_3_Patch_022
Siemens · COMOS Version 10 <=Patch_004

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more