Access Control Vulnerability in COMOS by Siemens
CVE-2023-43505
6.5MEDIUM
Summary
A significant access control vulnerability has been discovered in COMOS across all versions. The application inadequately implements access controls for SMB shares, which can potentially allow unauthorized users to access files that are meant to be restricted. This security flaw raises concerns about data privacy and integrity, as malicious actors may exploit this weakness to retrieve sensitive information. Organizations using COMOS are advised to review their security configurations and implement appropriate measures to mitigate potential risks.
Affected Version(s)
COMOS All versions
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved