Comos

Vendor:

First CVE: Aug 16, 2012 · Active for 13 years

31
Total CVEs
More Total CVEs than 96% of tracked products
6.2
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Comos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2012
13 years ago
Most Recent CVE
Nov 14, 2023
984 days ago

CVE Severity & Scoring

Comos31 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local15 (48.4%)
Network12 (38.7%)
Unknown4 (12.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (83.9%)
High1 (3.2%)
Unknown4 (12.9%)
User Interaction
None10 (32.3%)
Unknown4 (12.9%)
Required17 (54.8%)
Privileges Required
Low3 (9.7%)
High0 (0.0%)
None24 (77.4%)
Unknown4 (12.9%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa
Dec 14, 20219.098YESYES
A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (Al
Feb 14, 20239.828NONO
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10
Jan 11, 20228.828NONO
A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structu
Nov 14, 20239.827NONO
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10
Jan 11, 20228.827NONO
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DX
Jan 18, 20217.827NONO
An out-of-bounds write issue exists in the DGN file-reading procedure in the Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of user-supplied d
Jun 17, 20217.826NONO
An out-of-bounds write issue exists in the DWG file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-suppli
Jun 17, 20217.826NONO
An out-of-bounds write issue exists in the DXF file-recovering procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-sup
Jun 17, 20217.826NONO

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
2 CVEs
6.5% of CVEs· 97th percentile
Metasploit
2 CVEs
6.5% of CVEs· 97th percentile
Nuclei
2 CVEs
6.5% of CVEs· 97th percentile
ExploitDB
1 CVE
3.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Comos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2.0.6.1016.90.3%00
9.246.80.8%00
9.117.20.4%00
4.116.10.5%00
10.438.00.7%00
10.217.50.9%00
10.116.90.3%00
10.0.3.0.416.90.3%00
10.046.80.8%00