PT-2024-36012 · Siemens · Comos

Published

2024-12-10

·

Updated

2024-12-10

·

CVE-2024-54005

CVSS v3.1

5.1

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: COMOS V10.3 versions prior to V10.3.3.5.8 COMOS V10.4.0 versions prior to V10.4.0 COMOS V10.4.1 versions prior to V10.4.1 COMOS V10.4.2 versions prior to V10.4.2 COMOS V10.4.3 versions prior to V10.4.3.0.47 COMOS V10.4.4 versions prior to V10.4.4.2 COMOS V10.4.4.1 versions prior to V10.4.4.1.21
Description: The PDMS/E3D Engineering Interface in COMOS improperly handles XML External Entity (XXE) entries when communicating with an external application. This could allow an attacker to extract any file with a known location on the user's system or accessible network folders by injecting malicious data into the communication channel between the two systems.
Recommendations: For COMOS V10.3 versions prior to V10.3.3.5.8, update to version V10.3.3.5.8 or later. For COMOS V10.4.0, update to a version that is not affected by this issue. For COMOS V10.4.1, update to a version that is not affected by this issue. For COMOS V10.4.2, update to a version that is not affected by this issue. For COMOS V10.4.3 versions prior to V10.4.3.0.47, update to version V10.4.3.0.47 or later. For COMOS V10.4.4 versions prior to V10.4.4.2, update to version V10.4.4.2 or later. For COMOS V10.4.4.1 versions prior to V10.4.4.1.21, update to version V10.4.4.1.21 or later. As a temporary workaround, consider restricting access to the PDMS/E3D Engineering Interface to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-54005

Affected Products

Comos