← Back to home
ICSA-23-047-10  ·  Published 2023-02-14  ·  View on CISA ICS-CERT ↗

Siemens COMOS

CVSS 10.0 CRITICAL

CVEs (1)

Remediations

  • Enable Structured Exception Handling Overwrite Protection (SEHOP) in your Windows Operating System where COMOS is installed to protect against code execution. However, the application is still vulnerable to denial of service attacks
  • Currently no fix is planned
  • Update to V10.3.3.1.45 or later version
  • Update to V10.3.3.2.33 or later version
  • Update to V10.3.3.3.9 or later version
  • Update to V10.3.3.4.6 or later version
  • Update to V10.4.0.0.31 or later version
  • Update to V10.4.1.0.32 or later version
  • Update to V10.4.2.0.25 or later version

Affected Vendors

Siemens

Affected Products (8)

Siemens · COMOS V10.2 vers:all/*
Siemens · COMOS V10.3.3.1 <V10.3.3.1.45
Siemens · COMOS V10.3.3.2 <V10.3.3.2.33
Siemens · COMOS V10.3.3.3 <V10.3.3.3.9
Siemens · COMOS V10.3.3.4 <V10.3.3.4.6
Siemens · COMOS V10.4.0.0 <V10.4.0.0.31
Siemens · COMOS V10.4.1.0 <V10.4.1.0.32
Siemens · COMOS V10.4.2.0 <V10.4.2.0.25

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more