CVE-2023-43504: Siemens Comos

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition.

Affected products

  • Siemens Comos: before 10.4.4 (fixed in 10.4.4)

Published 2023-11-14. Last modified 2026-06-17.