CVE-2023-24482: Siemens Comos

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All versions < V10.4.0.0.31), COMOS V10.4.1.0 (All versions < V10.4.1.0.32), COMOS V10.4.2.0 (All versions < V10.4.2.0.25). Cache validation service in COMOS is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition.

Affected products

  • Siemens Comos: from 10.2, before 10.3.3.1.45 (fixed in 10.3.3.1.45); from 10.3.3.2, before 10.3.3.2.33 (fixed in 10.3.3.2.33); from 10.3.3.3, before 10.3.3.3.9 (fixed in 10.3.3.3.9); from 10.3.3.4, before 10.3.3.4.6 (fixed in 10.3.3.4.6); from 10.4.0.0, before 10.4.0.0.31 (fixed in 10.4.0.0.31); from 10.4.1.0, before 10.4.1.0.32 (fixed in 10.4.1.0.32); …

Published 2023-02-14. Last modified 2026-06-17.