A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks.
2022-01-11T12:15:09.983
2025-05-22T19:15:25.320
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | siemens | comos | ≤ 10.2 | Yes |
| Application | siemens | comos | < 10.3.3.3 | Yes |
| Application | siemens | comos | 10.4 | Yes |