10
CVSSv3

CVE-2021-37181

Published: 14/09/2021 Updated: 24/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated malicious user to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens cerberus dms 4.0

siemens cerberus dms 4.1

siemens cerberus dms 4.2

siemens cerberus dms 5.0

siemens desigo cc 4.0

siemens desigo cc 4.1

siemens desigo cc 4.2

siemens desigo cc 5.0

siemens desigo cc compact 4.0

siemens desigo cc compact 4.1

siemens desigo cc compact 4.2

siemens desigo cc compact 5.0