CVE-2024-49704 is an XML External Entity (XXE) vulnerability affecting multiple versions of Siemens COMOS software, specifically within the Generic Data Mapper, Engineering Adapter, and Engineering Interface components. An attacker could exploit this by convincing a user to process a maliciously crafted configuration or mapping file, leading to the extraction of sensitive files from the user's system or accessible network shares. Rated with a CVSS score of 5.5 (Medium), this vulnerability requires user interaction and local access, but can result in high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | COMOS V10.3 | >= 0, < V10.3.3.5.8CNA affecteddefault unknown | |
| Siemens | COMOS V10.4.0 | >= 0, < *CNA affecteddefault unknown | |
| Siemens | COMOS V10.4.1 | >= 0, < *CNA affecteddefault unknown | |
| Siemens | COMOS V10.4.2 | >= 0, < *CNA affecteddefault unknown | |
| Siemens | COMOS V10.4.3 | >= 0, < V10.4.3.0.47CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.