CVE-2023-43504 CRITICAL

CVE-2023-43504

Vendor Siemens
Product COMOS
Weakness CWE-120
Published November 14, 2023
Last update January 8, 2025

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

What the vulnerability does

01Description

A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition.

Key dates

02Disclosure timeline

November 14, 2023 CVE published
January 8, 2025 Record updated